Random Password Generator:

Assuming each password character is chosen from a pallet of 72 possible characters, then each time one adds a character to one's password, one makes it 72 times more difficult to break. Thus, a 15 character password is 72^7 times as hard to break as an 8 character password. That's 10,000,000,000,000 times harder to break.

A 15-character password composed only of random letters and numbers (a-z0-9) is about 33,000 times stronger than an 8-character password composed of characters from the entire keyboard.


How They Are Generated:

It would be illogical of us to fully explain this question, as that would allow folks to Reverse engineering what we are doing... which would just be stupid of us to allow - as this would jeopardize our passwords crypto-strengths!

Here is what we will share:

First we acquire some randomized numbers from Random.Org which is a service that provides truly random numbers. As they put it at their website, "RANDOM.ORG offers true random numbers that comes from atmospheric noise, which for many purposes is better than the pseudo-random number algorithms typically used in computer programs.". We will not say how many columns we use, nor what the integer values we use are, but you can generate some of your own at their website to see how it works. :)

Secondly we do some base to decimale stuff to make some changes between what random.org uses and what we need. All grunt-work-stuff on our end to make the programming-language we use happy with the stuff that random.org provides. While doing so we use throw in some additional unique randomization in order to produce a nice healthy seed.

Thirdly we take our randomized numbers and srand them just for the fun of it.

Fourthly we take the above "randomized number" -> "srand number" and seed it with the characters allowed within each section below. (i.e.: a-z, a-z0-9, a-z + 0-9 + A-Z + Symbols, a-z + 0-9 + A-Z + Symbols + Space + ANSI)

Fifth we validate that the strings are the right length. (i.e.: 6-chars, 15-chars, 124-chars) Excitting Huh!

Sixthly we validate that none of the strings contain any random characters not allowed within the given section to be passed along. (a menial task that we do just for you!)


Passwords Strengths:

Below we will start by displaying some pretty worthless passwords (easily broken by a brute force attack), then move onto some more pretty worthless passwords, and work our way into more and more secure passwords. It is safe to say that the "probably unbreakable" passwords are just that... unbreakable -- even with most modern super computers. Of course, we do not place any warranty that they c/would not be... but it is highly unlikely that they could be. Of course, one has to ask, "how in the world could a person be expected to remember any of the 'probably unbreakable' passwords?" -- to which we do not have an answer. Obviously writing them down greatly increases the risk that somebody might find it and try it. Use at your own risk ;)

All that said, remember that if you are not a big-fan of passwords, there is such a thing as a Passphrase -- which many people consider to be much more secure then a password!

If one takes into consideration a modern chipset and a budget of $1 billion (100 million custom coded encryption CPU engines in parallel), with some of the most efficient brute-force systems available, it is possible to crack a 128 bit encrypted volume in only 1,000 billion years. Of course the important part to remember here is that if the encryption key is either derived from a password, or is encrypted by a hash of a password, then $12M worth of equipment should be able to crack it in about 3 hours and $1B of equipment should crack it in about 2 minutes or so.

What is key to all of this is that cracking encryption methods is not always about using brute force against keys, but rather that guessing passwords which are derived by weak password generators are much more important to realise and use. How one generates keys and what one does to protect their keys is the crucial step to any level of security. It really does not matter if a key length takes a billion years to crack if the process of guessing the password itself only takes a few hours because they are not generated correctly!


A Word Of Caution:

Obviously we are taking security seriously with the below passwords (even for the weak/worthless ones) but you should not use ANY of the below passwords that are lower in security then our "Secure" level for MS Window passwords or for WEP/WPA keys. The reason for this is that some very popular and easy to use tools already exist to acquire these with very little effort.

This is especially true for MS Windows user-account passwords, because any that are UNDER 14-characters can be cracked with almost no effort at all, regardless of the version of Windows, so it is best to use passwords/passphrases that are greater then 14-characters in length for your Windows Users Account Password.

As for how long and strong you should use for WEP/WPA Keys, it is our belief that unless you are running a Cisco wireless network, or third-party software, wireless security is non-existent, regardless of how long or strong of a password/passphrase you use. Simply put, there are just too many software programs out there that are able to sniff or force wireless passwords. Your best solution is to either disable wireless or go with an option that provides wireless security outside the boundaries of WEP/WPA.


And Now, Here Are Some Passwords:

(don't like any... just refresh the page)



Completely Worthless: (6-chars in length, including: a-z)

oijgud
lidolq
zbrymm
urnhlv
djvqwe


Worthless: (6-chars in length, including: a-z + 0-9)

813f98
f02fc0
89fdda
493c34
7658a0


Weak: (8-chars in length, including: a-z + 0-9)

c43qhbeo
cj16maqo
s7y6qww4
avufj70o
tcag2y1w


Strong: (8-chars in length, including: a-z + 0-9 + A-Z)

T4nkWQi1
mKxayy3
pnKA3gG8
tEz5QPhh


Fairly Strong: (12-chars in length, including: a-z + 0-9 + A-Z)

Rp4R85ZkFDX2
vNW56YgmzYke
Wt5CJedmniv1
WZgFCQbDFIhF
qQFgbEFNMpwS


Secure: (15-chars in length, including: a-z + 0-9 + A-Z + Symbols)

=M8!##@@3%%=&R7
r*H#De+@txh!a5J
pqWjEqMVMfhUHZq
+3~aIpvBHq=hY5w
HkAp5@Le%Abeuw~


Very Secure: (24-chars in length, including: a-z + 0-9 + A-Z + Symbols)

57lnva4U%=#=v2&U!4UIw~U
wmbfvmWAmkWbjMQ&hRJp*J=
=@UE72BJMxd8l5Lja-dj3wh
xMB^ZaIAW8Im&Su2mIfm~A@
WI+7BBkKLH#x73&vn^k*JblZ


Highly Secure: (36-chars in length, including: a-z + 0-9 + A-Z + Symbols)

vb#SLMV2IJM&AR%@f5h@a+Kk8W#HLZHaQp+7
fv#UvxIx@^U82xnIbk&n7kK*R3%VpjJUUJp2
KhuZ+*7Rx@3pSVSa*WInUIn*%wf7Zl!Hb%
ufU^!33f7RkJlWAZZLaU&2J&@!fRQMQKuLu
AS*WkSKapW^uaV5Qn3b2#AaafxRSuff3wL


Extremely Secure: (64-chars in length, including: a-z + 0-9 + A-Z + Symbols - TrueCrypt optimized)













Probably Unbreakable: (64-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)













Highly Unbreakable: (124-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)













Highly Useful: (128-chars in length, including: a-z + 0-9 + A-Z)













Almost Unbreakable: (255-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)













Unrealistically Unbreakable: (512-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)







Dare-We-Say Unbreakable?: (1024-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)








Updates & Changes:

6/16/2010 -- We resolved a small issue with the "Completely Worthless", "Worthless" and "Weak" passwords that was pointed out to us by a school employee. We did not think people would actually use them so we never double-checked them for duplication cycles. Oops.

10/19/2009 -- We added the "Highly Useful: (128-chars in length, including: a-z + 0-9 + A-Z)" set today. We should have no real security value as it is just a randomized 128-character string with no security checking for things such as consistent character checking, which is important in alpha-numeric only strings. This is more to just give those of you needing 128-character strings a quick way to have some.

9/6/2009 -- We added the "Almost Unbreakable: (255-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)" set today due to request from a developer that uses (max) 255-character passwords.

3/8/2009 -- We added two more sets of passwords today. The "Unrealistically Unbreakable" a huge 512-character string and our first "Dare-We-Say Unbreakable?" password, with a massively insane 1024-characters in length! Note that both of these use [space] and it does NOT strip the [space] if the [space] occurs at the end of the password - by design. These two additional sizes where added due to requests we have received for even long passwords than our previously 124-character passwords! Because of the size and time it takes to produce these longer passwords, we are only displaying two of them at any given time.

9/14/2008 -- We added two more sets of passwords today. The "Extremely Secure" and "Probably Unbreakable", both 64-character passwords in length. Note that the "Probably Unbreakable" DOES use [space] and it does NOT strip the [space] if the [space] occurs at the end of the password, by design. The 64-character password is a popular length by many hard drive volume cryptograph programs (including TrueCrypt) and we've gotten a number of requests to add this length.

Updated: 7/7/2008 -- We made three changes to the "probably unbreakable" level passwords today.
  1. Added: - We now generate a password that is three times longer then necessary, then generate a randomized start/end point and from there, "splice out" a 128-character password. This extra level of randomization will further increase the "true randomness" of this process. Rather then our software always using a specific start/end point, by generating this extra large password and then randomly splitting out a section of the extra large password, it will make it that much more unlikely to have problems with duplication factors. It is beyond our math abilities to compute what increase of to-the-nth-power of randomness this gives us, so that is saying something.

  2. Updated: - We have also increased the included characters by an additional 20 characters.

  3. Updated: - We have also made it so a random character will replace the first and/or last character if it was generated as a [space] to help reduce copy/paste errors.


Updated: 2/3/2008 -- Decided to add another step of randomization for all generated passwords that are "Fairly Strong" and above.
  1. Added: - We now randomize the "available characters" (i.e.: a-z, a-z0-9, a-z + 0-9 + A-Z + Symbols, etc) rather then using a set-pattern. We should have done this from the start, but neglected to do so. This extra step should truly make the "probably unbreakable" unbreakable to most modern non-super-computers! Unsure of the bit-level increase on this (and unwilling to share further details of what we have done to protect our methodology), but it is a huge increase to the overall bit-level!

· software that does what it was designed to do ·