Most password advice fixates on complexity: add a symbol, capitalize a letter, swap an "e" for a "3". It feels like it should help. The math says otherwise, length does almost all the work, and most advice underweights it.
Try it yourself
Drag the slider below. This estimates how long an offline brute-force attack, guessing 10 billion combinations a second, a realistic rate for modern cracking hardware, would take against a fully random password using upper, lower, numbers, and symbols.
Notice the jump isn't gradual. Somewhere around 12–14 characters, the number of possible combinations grows so fast that "instantly crackable" turns into "longer than the age of the universe" within just a few more characters. That's why length beats clever substitutions almost every time.
Where generators actually fail
Not every "random" generator is what it claims. Some older or poorly built tools use pseudo-random functions, ones seeded from something predictable like the current time, rather than a cryptographically secure source. In theory, that narrows the guessing space far more than the character count suggests. A generator worth using draws from your browser's or system's cryptographic random source, not a plain-JavaScript Math.random() call.
What to actually do with this
Use a generated password of at least 16 characters for anything that matters, email, banking, your password manager's own master password. Never reuse one across sites. And don't try to memorize them, that instinct is what pushes people back toward weaker, patterned passwords in the first place.
Generate one now, cryptographically random, right in your browser.
Open the generator