Password Generator Security: Strong Passwords Done Right
A generated password is only as strong as its randomness source and its handling. Here is the security-focused method I use. Password generators are essential for security and also a source of subtle failures. A generated password is only as strong as the randomness behind it and the process that manages it after generation. I have used password generators for years and have learned where they fail and how to use them so they actually protect accounts. Here is the security-focused approach I take. Randomness Source Determines Strength The strength of a generated password comes from entropy, and entropy comes from the randomness source. A generator that uses a weak random function, like the default math random in many languages, produces passwords that look random but are predictable. An attacker who knows the algorithm and the time of generation can reproduce the password. I only use generators that rely on a cryptographically secure random number generator. In the browser, that is the Crypto API, which draws from the operating system entropy pool. A generator that uses math random is unsuitable for any password that protects something valuable. The output looks identical, but one is unpredictable and the other is guessable. More tutorials are on the KitCraft Blog.