crypto.getRandomValues() picks characters uniformly from your chosen sets.
A password generator creates long, random passwords that no human would invent — and that no attacker can guess. Human-chosen passwords follow predictable patterns (names, dates, "Password123!"), which is exactly what guessing attacks exploit. A generator picks each character at random from a large set, producing passwords with far more unpredictability per character than anything you'd type yourself.
The generator uses a cryptographically secure random number source (not the predictable pseudo-random functions used in games) to select each character independently from the character sets you enable:
Password strength is measured in bits of entropy: entropy ≈ length × log₂(alphabet size). A 16-character password drawn from all 94 printable ASCII characters has about 16 × 6.55 ≈ 105 bits of entropy — meaning an attacker would need to try roughly 2¹⁰⁵ combinations on average to guess it, which is infeasible with any realistic computing power. Every extra character multiplies the search space, so length matters more than clever substitutions like "@" for "a".
Compare two example passwords (illustrative only — never reuse these):
AhmedDubai2026! — 14 characters, but built from predictable words and a year. Its real-world guessing resistance is far below what its length suggests.7#kQ9!mzV2@xLp4$wT — 18 random characters from a 94-symbol alphabet ≈ 18 × 6.55 ≈ 118 bits of entropy. No pattern, no dictionary words, no personal information.The second password is effectively unguessable, while the first could fall to a targeted guessing attack.
No — generation happens entirely in your browser with the Web Crypto API.
16+ characters with mixed sets resists brute force for the foreseeable future.