Password and passphrase generator
Create strong, random passwords or memorable passphrases with a live strength estimate. Generated in your browser and never sent anywhere.
Generate a password or passphrase
Length
20 charactersOffline crack estimate: Trillions of centuries (critical infrastructure)
Generated locally via Web Cryptography API (crypto.getRandomValues) and never transmitted.
Tired of managing shared WiFi passwords across your venues?
Shared pre-shared keys leak when employees leave. Purple enables 802.1X enterprise authentication, individual tenant PPSKs, and automated onboarding across Cisco Meraki, Aruba, Ruckus, and Juniper Mist.
Stronger credentials, fewer breaches
Reused and short passwords are behind most account takeovers. A long random password or a multi-word passphrase raises the cost of a brute-force attack far beyond what attackers will spend. This generator uses your browser's cryptographic random number generator, so the output never leaves your device.
What this tool gives you
- Random passwords with control over length and character sets, including an option to drop look-alike characters.
- Readable passphrases built from a word list, with separators, word casing, and an optional number.
- A live entropy estimate in bits so you can see how strong each result is before you use it.
Entropy and brute-force cracking benchmarks
Theoretical crack times against an offline 100 billion guess-per-second GPU cluster (standard modern 8x GPU hashcat cracking array). Aligned with NIST SP 800-63B credential recommendations.
| Credential type | Length / composition | Entropy | Offline GPU crack time | Security tier |
|---|---|---|---|---|
| Short alphanumeric | 8 chars (letters + digits) | ~48 bits | 3.6 hours | Vulnerable |
| Standard WiFi password | 16 chars (full charset) | ~105 bits | 130 billion years | Strong |
| WPA3 / Enterprise PSK | 24 chars (symbols + letters) | ~157 bits | Uncrackable | Enterprise grade |
| RADIUS shared secret | 32 chars (hex / ascii) | ~210 bits | Uncrackable | Critical infrastructure |
| 5-Word Diceware phrase | 5 words + 2 digits | ~72 bits | 1.5 million years | Human memorable |
Frequently asked questions about password security and entropy
How does password entropy measure security strength?
Entropy measures the randomness and unpredictability of a credential in bits. Each additional bit doubles the number of guesses an attacker must test. An 80-bit password requires over one septillion attempts to brute-force, providing protection against offline GPU cracking clusters.
What is the recommended password length for WiFi networks?
For WPA2-Personal networks, use a minimum of 20 characters containing uppercase, lowercase, numbers, and symbols to resist dictionary attacks. WPA3-Personal networks use Simultaneous Authentication of Equals (SAE) to block offline dictionary attacks, but still require at least 16 to 24 characters for enterprise resilience.
How long should a RADIUS shared secret be?
A RADIUS shared secret between network access points or controllers and an authentication server should be at least 24 to 32 characters long. High-entropy random strings prevent offline HMAC-MD5 packet decryption and rogue authenticator injection.
Why are multi-word passphrases more secure than complex short passwords?
Passphrases made of five or more random words provide over 60 to 80 bits of entropy while remaining easy for human memory to retain. They eliminate keyboard typing errors and reduce the temptation to write credentials down on sticky notes.
Does this password generator store or transmit generated credentials?
No. The generator runs entirely within your client browser using the Web Cryptography API (crypto.getRandomValues). No generated passwords, passphrases, or entropy parameters are ever transmitted to or stored on Purple servers.
Enterprise WiFi security architecture and guides
Explore technical blueprints and tools for eliminating shared wireless passwords across your physical locations.
Enterprise WiFi security guide
Learn how 802.1X, PPSK, and WPA3-Enterprise protect corporate networks without shared credentials.
WPA3-Personal vs WPA3-Enterprise
Understand SAE handshakes, 192-bit cryptographic suites, and transition mode trade-offs.
RADIUS setup guide
Step-by-step configuration for FreeRADIUS, Cisco ISE, and Aruba ClearPass integrations.
Multi-tenant iPSK subnet designer
Design isolated private subnets and DHCP scopes for student housing and build-to-rent properties.
Securing your WiFi estate?
Strong credentials are step one. Purple adds WPA2 and WPA3 Enterprise onboarding, per-tenant PPSK, and 802.1X across Cisco Meraki, HPE Aruba, Ruckus, and Juniper Mist so staff and guests connect without shared secrets.
Book a 20-min demoNetforge Network Multi-Tool
Run offline network health checks, path analysis, and latency diagnostic scans directly from your desktop.
Download Multi-Tool