Strong, genuinely random passwords generated in your browser. Nothing is sent anywhere and nothing is stored.
Generated with your browser’s cryptographic randomness, never sent anywhere, and deliberately not saved — browser storage would leave passwords readable in plain text. Copy yours into a password manager.
A good password is long and unpredictable. Both come from generating it rather than inventing one, because people are poor sources of randomness.
Sixteen characters or more for anything that matters. Length does more for strength than any other setting.
Letters, numbers and symbols. At least one of every enabled type is guaranteed to appear, and you can exclude similar-looking characters if you will be typing it by hand.
Copy the password straight into your password manager. Nothing is saved here, so once the tab closes it is gone for good.
Anywhere you would otherwise reuse one you already know.
Start every sign-up with a unique password rather than a variation of an old one.
Replace a password immediately once a service reports it may have been exposed.
Set a guest network password that is long but easy enough to read from a card.
Protect a locked PDF or archive with something far stronger than a memorable phrase.
Give machine accounts long random strings, since nobody has to remember them.
Work through the accounts still sharing one password and give each its own.
Generating the password is the easy part. What you do next decides whether it helps.
How the randomness works and why nothing is saved.
Set the length, choose which character types to include, and generate. The randomness comes from your browser’s cryptographic generator, not a predictable formula, and the result never leaves your device.
Other things you can do here without signing up.