</>
DevToolBox Private, Client-Side Developer Utilities

Guide · Security

Generating and Storing Strong Passwords Properly

Most password advice focuses on complexity: an uppercase letter, a digit, a symbol. That advice comes from an era when attackers guessed passwords one at a time over a network. Modern attacks take a stolen hash database and test billions of candidates per second on a GPU. Against that, length matters far more than complexity.

Entropy is the number that matters

Password strength is measured in bits of entropy, which is a function of how randomly the password was chosen and how large the pool it was chosen from was:

As a practical target, aim for at least 80 bits for anything that matters. A random 14-character password, or a five-word passphrase, clears that comfortably.

What does not work

Generating a password safely

Use a generator driven by a cryptographic random source. In a browser that is crypto.getRandomValues(); on the command line it is /dev/urandom, openssl rand or gpg --gen-random. Never use Math.random(), and never use a generator that derives its output from a date or a seed you can guess.

Our password generator uses the browser’s cryptographic API and runs locally, so the generated value is never transmitted, logged or stored anywhere.

One caveat about online generators in general: a page can only be trusted if the generation happens in the browser, which you can verify by watching the network tab. A generator that sends a request when you click “generate” may be receiving your password.

Storing dozens of credentials

Once you stop reusing passwords, you need somewhere to keep them. A reputable password manager is the answer. Look for:

  1. End-to-end encryption with a key derived from your master password, so the provider cannot read your vault.
  2. An audited, open or well-documented cryptographic design.
  3. A track record and a published security contact.
  4. Optional hardware-key or app-based second factor on the vault itself.

Keep an offline backup of the vault — an exported, encrypted copy on a physical device you control. Forgetting a master password with no backup means losing every credential at once.

Turn on a second factor

Even a perfect password can be phished. A second factor defeats it. In descending order of strength:

Save the recovery codes when you enable a second factor, and store them somewhere other than the device that generates the codes.

A checklist

  1. One unique password per account, generated randomly, at least 14 characters.
  2. A password manager holding everything, protected by one long passphrase plus a second factor.
  3. Hardware keys on email, banking and cloud consoles.
  4. An encrypted offline backup of the vault.
  5. Rotate immediately if a service you use reports a breach.

← Back to all guides