Password Generator Entropy Explained, Pools Bits and Bias

Strength meters hand out labels. Entropy gives you a number you can check with a calculator. Our password generator ships with a 62 character default pool and a 16 character default length, and those two facts fix the strength of everything it prints. Here is the arithmetic, plus one bias in our own code that we will not hide.

Pool Sizes and Entropy per Character

The default configuration turns on uppercase, lowercase, and digits. That pool is 26 plus 26 plus 10, or 62 characters. Each character drawn from it carries log2 of 62, about 5.95 bits of entropy. Switching symbols on adds the 26 character symbol string and grows the pool to 88, which carries about 6.46 bits per character.

Multiply by length to get total entropy, assuming every character is drawn uniformly.

Length62 character pool88 character pool
635.7 bits38.8 bits
1271.5 bits77.5 bits
1695.3 bits103.4 bits
64381.1 bits413.4 bits

The default output, 16 characters from the 62 character pool, sits near 95 bits. Turning symbols on adds about 8 bits at the same length. Length beats complexity in this table. Twenty characters drawn from lowercase alone, a 26 character pool, gives 94 bits, while 8 characters from the full 88 pool give only 51.7.

Where the Randomness Comes From

The generator fills a Uint32Array with crypto.getRandomValues, the browser interface to the operating system's cryptographic generator. Each character position gets its own 32 bit random value. This is the correct primitive, and it is the entire reason the output is unpredictable. Generators built on Math.random are predictable from observed output, and ours does not touch it.

The Modulo Bias in Our Own Code

Character selection is arr[i] % pool.length. A 32 bit value covers 4,294,967,296 possibilities. With the default 62 character pool, that space splits into 62 equal shares of 69,273,666 with a remainder of 4. Four characters in the pool get one extra share of the draw.

The tilt is about one part in 69 million per character. It is far too small to help any guessing attack, because attacks fail on the 95 bits, not on the bias. But it is real, and we will not claim our code uses rejection sampling when it does not. The clean fix is to discard values above the largest multiple of the pool size and redraw. We have not shipped that fix, and this paragraph is the honest status.

What the Strength Meter Rewards Instead

The meter scores five checks, length at least 8, length at least 14, contains uppercase, contains a digit, and contains a non-alphanumeric character. The score caps at an index of 4 across the five labels from Very Weak to Very Strong.

Two consequences follow from those exact rules.

An 8 character password with an uppercase letter, a digit, and a symbol scores 4 and displays Very Strong. Its entropy at the full pool is 51.7 bits.

A 20 character lowercase-only password scores 2 and displays Moderate. Its entropy is 94 bits.

The meter rewards character classes, not entropy, and it never checks for lowercase at all. When the label and the table disagree, trust the table. Set the slider past the label.

Settings We Recommend

1. Leave length at 16 or above. Push to 20 or more for master passwords and encryption keys, with 64 as the ceiling.

2. Switch symbols on unless the target system rejects them. The pool moves from 62 to 88.

3. Check the symbol string before you commit to it. It contains shell-significant characters such as the pipe, semicolon, and angle brackets, and some login forms refuse them.

4. Copy with the button, not by selecting text. The clipboard copy avoids a trailing space or a missed character.

5. Treat every output as disposable. The generator stores your length and set choices in localStorage, but the passwords themselves live only in page memory, and a refresh wipes the list.

The honest cost of that last point is loss. If you generate a password, paste it somewhere unsafe, refresh, and lose it, you regenerate and update. No history exists on our side either, which is the same property that makes the tool safe to use on a shared machine.

Checklist

  • [ ] You set length to at least 16, or 20 for high-value accounts.
  • [ ] You switched symbols on unless the target form rejects them.
  • [ ] You computed your entropy from the table instead of trusting the label.
  • [ ] You pasted the password into your manager before closing the page.
  • [ ] You accepted that no output is recoverable after refresh.

Open the [password generator](/en/password-generator), set your real configuration, and compute your bits from the table above. If your number differs from ours, check the pool size first and send us the configuration, because a wrong pool size in this article would be a bug we want to fix.