Random Password Generator:

Assuming each password character is chosen from a pallet of 72 possible characters, then each time one adds a character to one's password, one makes it 72 times more difficult to break. Thus, a 15 character password is 72^7 times as hard to break as an 8 character password. That's 10,000,000,000,000 times harder to break.

A 15-character password composed only of random letters and numbers (a-z0-9) is about 33,000 times stronger than an 8-character password composed of characters from the entire keyboard.


How They Are Generated:

It would be illogical of us to fully explain this question, as that would allow folks to Reverse engineering what we are doing... which would just be stupid of us to allow - as this would jeopardize our passwords crypto-strengths!

Here is what we will share:

First we acquire some randomized numbers from Random.Org which is a service that provides truly random numbers. As they put it at their website, "RANDOM.ORG offers true random numbers that comes from atmospheric noise, which for many purposes is better than the pseudo-random number algorithms typically used in computer programs.". We will not say how many columns we use, nor what the integer values we use are, but you can generate some of your own at their website to see how it works. :)

Secondly we do some base to decimale stuff to make some changes between what random.org uses and what we need. All grunt-work-stuff on our end to make the programming-language we use happy with the stuff that random.org provides. While doing so we use throw in some additional unique randomization in order to produce a nice healthy seed.

Thirdly we take our randomized numbers and srand them just for the fun of it.

Fourthly we take the above "randomized number" -> "srand number" and seed it with the characters allowed within each section below. (i.e.: a-z, a-z0-9, a-z + 0-9 + A-Z + Symbols, a-z + 0-9 + A-Z + Symbols + Space + ANSI)

Fifth we validate that the strings are the right length. (i.e.: 6-chars, 15-chars, 124-chars) Excitting Huh!

Sixthly we validate that none of the strings contain any random characters not allowed within the given section to be passed along. (a menial task that we do just for you!)


Passwords Strengths:

Below we will start by displaying some pretty worthless passwords (easily broken by a brute force attack), then move onto some more pretty worthless passwords, and work our way into more and more secure passwords. It is safe to say that the "probably unbreakable" passwords are just that... unbreakable -- even with most modern super computers. Of course, we do not place any warranty that they c/would not be... but it is highly unlikely that they could be. Of course, one has to ask, "how in the world could a person be expected to remember any of the 'probably unbreakable' passwords?" -- to which we do not have an answer. Obviously writing them down greatly increases the risk that somebody might find it and try it. Use at your own risk ;)

All that said, remember that if you are not a big-fan of passwords, there is such a thing as a Passphrase -- which many people consider to be much more secure then a password!

If one takes into consideration a modern chipset and a budget of $1 billion (100 million custom coded encryption CPU engines in parallel), with some of the most efficient brute-force systems available, it is possible to crack a 128 bit encrypted volume in only 1,000 billion years. Of course the important part to remember here is that if the encryption key is either derived from a password, or is encrypted by a hash of a password, then $12M worth of equipment should be able to crack it in about 3 hours and $1B of equipment should crack it in about 2 minutes or so.

What is key to all of this is that cracking encryption methods is not always about using brute force against keys, but rather that guessing passwords which are derived by weak password generators are much more important to realise and use. How one generates keys and what one does to protect their keys is the crucial step to any level of security. It really does not matter if a key length takes a billion years to crack if the process of guessing the password itself only takes a few hours because they are not generated correctly!


A Word Of Caution:

Obviously we are taking security seriously with the below passwords (even for the weak/worthless ones) but you should not use ANY of the below passwords that are lower in security then our "Secure" level for MS Window passwords or for WEP/WPA keys. The reason for this is that some very popular and easy to use tools already exist to acquire these with very little effort.

This is especially true for MS Windows user-account passwords, because any that are UNDER 14-characters can be cracked with almost no effort at all, regardless of the version of Windows, so it is best to use passwords/passphrases that are greater then 14-characters in length for your Windows Users Account Password.

As for how long and strong you should use for WEP/WPA Keys, it is our belief that unless you are running a Cisco wireless network, or third-party software, wireless security is non-existent, regardless of how long or strong of a password/passphrase you use. Simply put, there are just too many software programs out there that are able to sniff or force wireless passwords. Your best solution is to either disable wireless or go with an option that provides wireless security outside the boundaries of WEP/WPA.


And Now, Here Are Some Passwords:

(don't like any... just refresh the page)



Completely Worthless: (6-chars in length, including: a-z)

dbklli
zugter
yoztqg
jdpwoh
caymmk


Worthless: (6-chars in length, including: a-z + 0-9)

h85heg
zyondv
snbiuq
srv1i8
rwnrn6


Weak: (8-chars in length, including: a-z + 0-9)

2ropas6n
44gexjae
ptrnp1i5
lm3ckzki
peqk2woc


Strong: (8-chars in length, including: a-z + 0-9 + A-Z)

U8uTLqWW
kpqrL5Ps
Lh2a3xfU


Fairly Strong: (12-chars in length, including: a-z + 0-9 + A-Z)

zcSJXtdIAev
nuiYdNxzkR2Q
nFZXECMK5uBQ
GhySpdmke4Z
ej3C1rzPzDYj


Secure: (15-chars in length, including: a-z + 0-9 + A-Z + Symbols)

*n251xJj1c4!Qq
qB4ASBnf^MrbAWX
WZ-BNDnZ@%5g*K+
8*PUNqB%ktCrfte
7fPgxPD%c+&7@xC


Very Secure: (24-chars in length, including: a-z + 0-9 + A-Z + Symbols)

=JU1JS&IA%tuk~3Iupnprq-u
bImIeYAC!w6X!DPDL1*pxjYY
QAJwj-+UWPrA-bjZ+KbbqS!6
gVZ-plcD&qf5U=MQ+-#UC3+
k*6Pg+ee63rb#eYPCpg@JA~=


Highly Secure: (36-chars in length, including: a-z + 0-9 + A-Z + Symbols)

C~!16u@!u&CZ62cvu*C2gPJPJb1VcZgY&v2
Q6YDWgqqpC12eA#UMrY2UWv&Zql&ClbAKpb6
k~nCxrfMVUncZ!p6J&UALeKcl&c!YDVpjl-
jrbtqZl#2&kr~WKMxjp=QQv!etxMtVUCtp=3
tfQ23kKJJWv=reWVkJtt*#f*#uCVLlUA#pQQ


Extremely Secure: (64-chars in length, including: a-z + 0-9 + A-Z + Symbols - TrueCrypt optimized)

KL-xeZvLLQJAVMAC-evckx~3ZpQQK3l#uk~rfUALn-leCJ3eU#ZnvuupfrtAukn=

j3#lUcZlfx-3#rjK-*nu*DUuV2bAM*Mqb2u3=xkMqWbrcLb~pq~Ue~~fA3M*r*x1

K-*-cflUb13Z*-qtQCKJ#-Dte*bLxWWM~*krfKQZMk3xj1A2D-ffUuDl#nk=LKvr

AfUlf-uKrDl-MbenvnK23tAA#rVufeWcVKxnl23DutuArbQbxkjMuntWr3LLl*21

AeKk#KJlMx~K-feUAAVCZD#pDvJrJrq-Cju2=lV*cKUlUqJQbQupVqnL#Ar2ufWx



Probably Unbreakable: (64-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)

^bw#u‡Q,1i1'j@u‡}5U0-n=m^XMê!‡'46vp);u\;9r\:Vva)^u^#‡Lv^#e=M10A?

P}ncQ0];%7IsT'NGc:M6'.5&BwToBtRKhRŠnª1W©+ø/C)¼eRI\i6A©|DD6nu‡2~[

'+PhK%MIT=&c:¥©nYWbJxWUohL+=0cdül@ŽU[cGB``]uD%hMR-A&6RŠo}#1|'ibx

üR]ìk%PCH#pdVq}øbPmTm;t7¼I0øqoŠkø=3~vjX8{@Bª],(*sQj%|?dBNGŽqIŠ3O

EpD¥VJ9keelZ{G&^hZê-DETM?Adi`:êX?Kqs7e4%d^V;coYU'8t-:A8E7vPcH,ul



Highly Unbreakable: (124-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)

k=uü%U7Q]o/;E5TLüXGjQ6ª%\mª,+>{U2]mU^J-K-jdMOv2H5&ZŽa8U7/9E+xc3|füŠ'ThY8v^^jl1cq,5#,B-QZ]ªV!Arf:¼B3*`&c~5Dm,~Hê)acCêIne})?¥`

Y\\m@#Mio%wHr/Vc¼aH]o:AL'kkWjV{¼RlmlT0IV]E@TK*00YI6q¼XKcIjê¾D(K:8'u¥R*[;31>]=}!drVT]x!&]lQnPqp--|Rr-c!hhH@tN=R0%Dtc.sNHca©c5

-lE\&D^1~lq2ªeSpj-8*¾G:Y.‡QnSY7Cø0@pkN5:bZ¥+sxEJ%&}#mp‡LiXl|=pŠ¥ThD\XvêZa'#Si&I`~7SjqSøNf6?5@+xB&B}0(/;h2p]MMZif¼XuKK].C49:¼

©Bk&[¾©LqU4Q=IsG7[6e2DpC@[|r.6+kr|l\knNdeK7[1K;~(DKhsa@c9:|3m!#‡PIiNR^e@a‡BKGüt\)mA~ªH8Ž`iDQ(üq7MBTur?sB+\&,kGQ;us&[N!*k‡¥*\

#TuT‡]8PmB+AìJJø(xj>E¾¥r5IXZ©eV=@Švøc@UoU&/JHa'jp#]Idwì[/ê3iìnATjQê6}ìdhL!)ieW;rIu0sX‡}laU:fW5ZGŽ)kŠ&m;GBO?{e'MBêH|ês:h\Kti2



Highly Useful: (128-chars in length, including: a-z + 0-9 + A-Z)

2epm7p6uanygcp0iaeqrbnkbiyv86m5bb5ljhm8puu05ozpreuviby3p6frd61mnf145vz2d6hwelz18rmccdu5p40s4qv5zcsylwv2fvab2mp1a3o3sngfughnmazv3
8n5wh73m3q27nnf8c8188euuqgyziy7dv0awjasveqf5f5tbmer12qiomyn2io2u8cfenban78j5va86zmf2yuw8d6thwlrvh3wxhp0kanyeurt7nmswxrspjc2f17lg
o1d2hoynwx4i4j8kqvosim38fw2g1bdiabryb5godv4336x0a7bzslnnjd04hi6jo7eybbrmccl38wekvkmu58fv5l4zs1xph6ur2vxfhk6g77uuiekyfbukcuv8tqb7
zwllw3me1soisa6t74vy66v7my7546nv22ipthk3nhpcl03jqnxfh1md0tu6n1itusrzx5f2a11xveoqkeral357esdff4og27lawg7qcjdmz3f82c8c6puwo0w5d0iv
l8z6x07upg8jyvsri1ca2qej4qzmwo57321o45fthmnqwnz7gnesnoy1iknygursihnchdvgzcljo0kb61ar8dekgm7pe8v0fr6wiqr2toofamsyemzcnadfb8d27vuv


Almost Unbreakable: (255-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)













Unrealistically Unbreakable: (512-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)







Dare-We-Say Unbreakable?: (1024-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)








Updates & Changes:

10/19/2009 -- We added the "Highly Useful: (128-chars in length, including: a-z + 0-9 + A-Z)" set today. We should have no real security value as it is just a randomized 128-character string with no security checking for things such as consistent character checking, which is important in alpha-numeric only strings. This is more to just give those of you needing 128-character strings a quick way to have some.

9/6/2009 -- We added the "Almost Unbreakable: (255-chars in length, including: a-z + 0-9 + A-Z + Symbols + Space + ANSI)" set today due to request from a developer that uses (max) 255-character passwords.

3/8/2009 -- We added two more sets of passwords today. The "Unrealistically Unbreakable" a huge 512-character string and our first "Dare-We-Say Unbreakable?" password, with a massively insane 1024-characters in length! Note that both of these use [space] and it does NOT strip the [space] if the [space] occurs at the end of the password - by design. These two additional sizes where added due to requests we have received for even long passwords than our previously 124-character passwords! Because of the size and time it takes to produce these longer passwords, we are only displaying two of them at any given time.

9/14/2008 -- We added two more sets of passwords today. The "Extremely Secure" and "Probably Unbreakable", both 64-character passwords in length. Note that the "Probably Unbreakable" DOES use [space] and it does NOT strip the [space] if the [space] occurs at the end of the password, by design. The 64-character password is a popular length by many hard drive volume cryptograph programs (including TrueCrypt) and we've gotten a number of requests to add this length.

Updated: 7/7/2008 -- We made three changes to the "probably unbreakable" level passwords today.
  1. Added: - We now generate a password that is three times longer then necessary, then generate a randomized start/end point and from there, "splice out" a 128-character password. This extra level of randomization will further increase the "true randomness" of this process. Rather then our software always using a specific start/end point, by generating this extra large password and then randomly splitting out a section of the extra large password, it will make it that much more unlikely to have problems with duplication factors. It is beyond our math abilities to compute what increase of to-the-nth-power of randomness this gives us, so that is saying something.

  2. Updated: - We have also increased the included characters by an additional 20 characters.

  3. Updated: - We have also made it so a random character will replace the first and/or last character if it was generated as a [space] to help reduce copy/paste errors.


Updated: 2/3/2008 -- Decided to add another step of randomization for all generated passwords that are "Fairly Strong" and above.
  1. Added: - We now randomize the "available characters" (i.e.: a-z, a-z0-9, a-z + 0-9 + A-Z + Symbols, etc) rather then using a set-pattern. We should have done this from the start, but neglected to do so. This extra step should truly make the "probably unbreakable" unbreakable to most modern non-super-computers! Unsure of the bit-level increase on this (and unwilling to share further details of what we have done to protect our methodology), but it is a huge increase to the overall bit-level!

· software that does what it was designed to do ·