← Tools

EuroVDC

Password generator

Create a random password or a word passphrase in your browser. Each draw uses the cryptographic generator built into the browser. EuroVDC never receives or stores it.

What a strong password actually needs

Length does more work than a forced symbol. NIST treats a long unique secret as stronger than a short password that only satisfies a character checklist. This page shows the bit estimate so you can see that difference. It does not call a password unbreakable.

What the bit number means

The line under the password is an entropy estimate. It counts how many yes-or-no guesses a stranger would need to land on this exact value, if they already know the length and which characters were allowed. It does not time a particular computer. For a random password the sum is length times log2 of the pool size. A pool of about 78 characters is about 6.3 bits per character, so 16 characters is about 16 times 6.3, which rounds to 101 bits. That is 2 to the power of 101 possible passwords of that shape, not 101 tries. For a passphrase the sum is the word count times log2 of the word-list size. The separator is fixed, so it adds nothing. Dropping look-alike characters shrinks the pool and lowers the number. Rejecting runs such as abc lowers it a little more; the figure on screen does not subtract that, so read it as a ceiling. Under 50 bits is short. From 50 to 69 is workable. 70 or more is strong. A colour bar on many other generators hides this arithmetic.

Length beats a symbol rule

A 16-character mix of letters and digits is already harder to guess than an 8-character password that adds one symbol. OWASP asks services to accept at least 64 characters. This tool starts at 12 and the presets continue to 128 and 256. Some forms still cut anything past 64, so keep those longer values in a password manager. Presets at 8 are omitted on purpose.

Put it in a password manager

A random password is not meant to be memorised. Bitwarden and KeePass are two examples of managers that keep a unique password per account. The master password of that manager should be a long passphrase you can remember. This page is not affiliated with either product.

Add a second factor

A password proves that someone knows a secret. A second factor, such as an authenticator app, still blocks a login when that secret leaks. SMS codes are weaker than an app because the phone number can be moved. Turn the second factor on for email, the registrar, and the server panel.

What this page does not do

It does not store a history, sync a vault, or recover a forgotten password. The optional breach check asks Have I Been Pwned whether the hash prefix has been seen. A clear result is not a promise that the password will stay secret after you reuse it.

Sources

The rules on this page follow public guidance. The product names below are examples, not partners.

FAQ

What does “101 bits” mean?
It is the entropy estimate for a 16-character password drawn from a pool of about 78 characters: 16 × log2(78) ≈ 101. Each extra bit doubles the number of possibilities. The page shows the same sum for the password you just generated, using the pool that is actually switched on.
Are the passwords stored?
No. Generation runs in your browser. EuroVDC does not receive the password, does not write it to a log, and does not keep it in a database. A refresh clears it.
Is each password actually random?
Yes. The page calls crypto.getRandomValues, the browser’s cryptographic generator. It does not use Math.random. Sampling avoids modulo bias, and each enabled character set contributes at least one character.
How often should I change it?
NIST does not ask you to rotate a strong unique password on a calendar. Change it when it may have leaked, when you shared it, or when you leave a shared account. Use a new password for each service.
When should I use a passphrase?
Use a passphrase when a person has to type or remember it, such as the master password of a manager. Use the random mode for servers, panels, and mailboxes. Six words is a workable start; eight words is stronger. The bit line shows which one you have.
Does the breach check send my password?
Only if you press the button. The browser hashes the password with SHA-1 and sends the first five hex characters to Have I Been Pwned. The password itself is not sent to that service or to EuroVDC. If the request fails, you can still copy the password.
Why is there no 8-character option?
Eight characters is a common minimum on old forms, and it is too short for a new secret. Some login forms still reject Turkish letters or a few symbols. If a form refuses the password, turn those sets off and generate again rather than shortening it below 12.