194 tools

Security Tools · · 4 min read

How to Create a Strong Password (and How Strong Is "Strong"?)

What actually makes a password strong, how entropy is measured, how long your passwords should be, and how to generate secure random ones for free.

A strong password is long and random. The simplest way to get one is to use a generator that relies on your device's cryptographically secure random number source — like the Toolbench Password Generator — and to set the length to at least 16 characters. Then store it in a password manager so you never have to remember it.

This guide explains why length beats cleverness, what the "bits of entropy" number means, and how to choose settings for different situations.

What makes a password strong?

Attackers don't guess passwords one at a time by hand. They run software that tries billions of combinations, starting with leaked passwords, dictionary words and predictable patterns like Summer2026!. A password is strong when it:

  1. Isn't in any leaked list or dictionary — which rules out anything a human invented.
  2. Is long enough that trying every combination is impractical.
  3. Is unique to one account, so a breach elsewhere can't unlock it.

Randomness handles the first point, length handles the second and a password manager handles the third.

How to generate a password with Toolbench

  1. Open the Password Generator.
  2. Drag the length slider (6 to 64 characters; it starts at 20).
  3. Choose character sets: A–Z, a–z, 0–9 and !@#$ symbols.
  4. Turn on Avoid look-alikes if the password will ever be read aloud or typed from paper — it removes characters like l, 1, I, O, o and 0.
  5. Copy the main password, or pick one of the four alternatives below it. Click Regenerate for a fresh set.

Passwords are generated with your browser's crypto.getRandomValues() — the same cryptographically secure source browsers use for encryption keys. They are created on your device and never sent anywhere or saved.

What "bits of entropy" means

Next to each password, the generator shows an estimate like "≈ 129 bits entropy". Entropy measures how many guesses a brute-force attack would need, on a doubling scale: every extra bit doubles the work.

For a truly random password it's calculated as:

entropy = length × log₂(number of possible characters)

With all four character sets on, there are 87 possible characters (26 + 26 + 10 + 25 symbols), so each character adds about 6.4 bits. The tool labels the result:

Entropy Label Roughly equivalent to
Under 50 bits Weak 7 or fewer random characters
50–74 bits Fair 8–11 random characters
75–99 bits Strong 12–15 random characters
100+ bits Very strong 16+ random characters

These numbers only apply to random passwords. A human-chosen password like Tr0ub4dor&3 has far less real entropy than its length suggests, because cracking tools know the substitution tricks people use.

How long should a password be?

  • Accounts in a password manager: 20 characters or more. You'll never type it, so there's no reason to go short.
  • Passwords you must type occasionally: 16 characters with look-alikes avoided.
  • Wi-Fi passwords: 16–20 characters, symbols optional, look-alikes avoided — people will type it on phones and TVs.
  • Your password manager's master password: consider a long passphrase of five or more random words instead, which is easier to type and remember.

Current guidance from security bodies such as NIST favours length over complexity rules and recommends against forcing periodic changes unless there's evidence of compromise.

Mistakes to avoid

  • Reusing passwords. One breached site then exposes every account using that password. Uniqueness matters more than cleverness.
  • Predictable patterns. Capitalising the first letter and adding 1! to the end is the first thing cracking tools try.
  • Storing passwords in plain notes or spreadsheets. Use a password manager with a strong master password.
  • Skipping two-factor authentication. Even a perfect password can be phished. Turn on 2FA wherever it's offered.

Frequently asked questions

Are generated passwords stored or sent anywhere?

No. They're created in your browser and never transmitted or saved — not even to your Toolbench account.

Is a 12-character password enough?

A truly random 12-character password using all character sets has about 77 bits of entropy, which rates as strong. Since a password manager can fill it in for you, going to 16 or 20 characters costs nothing and adds a large safety margin.

Do symbols make a password much stronger?

A little. Adding 25 symbols raises the possible characters from 62 to 87, adding about half a bit per character. Adding length helps far more: four extra characters add around 25 bits.

What does "avoid look-alikes" do?

It removes characters that are easy to confuse — l, 1, I, O, o, 0 and | — so a password can be read aloud or copied from paper without mistakes. It slightly lowers entropy, which the tool accounts for.

Should I change my passwords regularly?

Only if there's a reason, such as a breach notification. Forced periodic changes tend to push people toward predictable patterns, and current guidance recommends against them.

More guides

All guides →