High-Entropy Password & Passphrase Generator
Generate cryptographically secure passwords and EFF Diceware passphrases using browser Web Cryptography CSPRNG. Computes Shannon entropy in bits with zero server transmission.
100% Secure & Client-Side: Generated locally using browser Web Cryptography APIs. Never transmitted to external servers.
The Mathematical Foundations of High-Entropy Passwords
In modern information security, the strength of an authentication secret is defined not by how difficult it is for a human to memorize, but by its resistance to exhaustive mathematical enumeration (brute-force attacks). Formulated by mathematician Claude Shannon in his landmark 1948 paper A Mathematical Theory of Communication, information entropy measures the degree of uncertainty or randomness in a system.
For a password of length L drawn uniformly and independently from a pool of R possible characters, the total search space N and resulting entropy in bits E are governed by the equation:
E = L × log₂(R)Each additional bit of entropy doubles the computational effort required by an adversary to exhaust the keyspace ($2^E$ total permutations). A password possessing 128 bits of entropy matches the symmetric cryptographic key strength of AES-128, rendering offline brute-force cracking physically impossible under known laws of thermodynamics.
Entropy Benchmark Spectrum
| Entropy Range | Security Classification | Resistance Horizon | Typical Example |
|---|---|---|---|
| < 36 bits | Very Weak | Instantaneous crack (< 1 millisecond on commodity GPU) | Summer2025! |
| 36 - 59 bits | Moderate | Vulnerable to fast offline NTLM/MD5 GPU clusters | k9#mP2$x |
| 60 - 84 bits | Strong | Secure against online guessing and moderate offline rigs | Correct-Horse-Battery-Staple |
| 85 - 127 bits | Very Strong | Unbreakable by nation-state supercomputers for decades | 16-char random alphanumeric + symbols |
| ≥ 128 bits | Quantum / Military Grade | Exceeds the energy output of the sun to exhaust keyspace | 24+ characters random pool |
NIST SP 800-63B Architecture: Why Passphrases Trump Arbitrary Complexity
In June 2017, the United States National Institute of Standards and Technology radically revised federal identity guidelines with NIST SP 800-63B (Digital Identity Guidelines: Authentication and Lifecycle Management). NIST debunked decades of corporate password dogmas:
- Eliminate Mandatory Periodic Password Rotation: Forcing users to change passwords every 90 days actually reduces security. Users predictably increment trailing numbers (e.g.
Spring2025!→Summer2025!), producing trivial patterns that cracking engines exploit effortlessly. - Abolish Composition Rules: Mandating uppercase, lowercase, numbers, and symbols causes humans to adopt universal substitution templates (e.g. capitalizing only the first letter and appending an exclamation mark at the end).
- The Diceware Passphrase Paradigm: Originally conceived by Arnold Reinhold in 1995, Diceware selects random words from an indexed dictionary using dice rolls. A 5-word passphrase chosen from a 7,776-word list yields:5 × log₂(7,776) = 5 × 12.92 ≈ 64.6 bits of pure entropyBecause each word is a recognized English token, humans can memorize long strings without writing them on post-it notes, while automated crackers face over $2.8 \times 10^19$ combinations.
Cryptographic Quality: CSPRNG vs Pseudo-Random Math.random()
In web browsers, executing Math.random() generates numbers via algorithms designed solely for speed in graphical simulations, not security. Because their seed states are small and deterministic, an adversary observing several consecutive outputs can calculate all past and future values.
This utility strictly invokes window.crypto.getRandomValues(new Uint32Array(n)). This API interfaces directly with the host operating system's Cryptographically Secure Pseudo-Random Number Generator (CSPRNG), which continuously aggregates physical hardware noise (keystroke timings, network packet arrival jitter, thermal sensor readings) to ensure statistical independence.