passphrase generator
four random words are easier to remember and harder to crack than "P@ssw0rd42". generated locally with your browser's crypto-grade randomness - hit regenerate until you like one, then copy it. nothing is stored or sent.
two ways this runs: with javascript everything happens in your browser - nothing leaves your device. with javascript off, the button generates the passphrase once on our server with php's cryptographically secure random - done in memory, shown once, never stored or logged.
faq
- is the randomness real?
- yes - crypto.getRandomValues(), the browser's cryptographic random source seeded by the operating system. not Math.random().
- why words instead of characters?
- length is what defeats cracking, and humans can actually remember five words but not 40 random characters. word-based passphrases give you both.
- can you generate the same phrase twice?
- practically impossible. every word carries about 8 bits of randomness, so a 5-word phrase plus the number suffix has ~47 bits behind it - two identical phrases will essentially never happen by chance.
- should i use this offline?
- you can. load the page once, disconnect, regenerate as often as you want - the code runs entirely locally.