Generátor hesel - create strong random passwords in your browser
Password Generator Workspace
Uprav pravidla níže a vygeneruj tolik hesel, kolik potřebuješ.
Password Generator Quick Guidance
A short checklist for getting the strongest result out of the generator above.
Make it long
Go for at least 16 characters, and longer whenever a site lets you. Length is the single best thing you can do to keep a password safe.
Let it be generated
Do not make one up in your head. Anything that is easy for you to remember is usually already on a hacker's list of common guesses.
Save it in a manager
Keep it in a password manager such as Bitwarden, 1Password, KeePass, or LastPass. Then you never have to remember it, and every account can have a different one.
Mix the characters
Leave at least three of the four switches on: small letters, capital letters, numbers, and symbols. The more variety, the harder it is to guess.
Skip look-alikes only by hand
Turn on 'exclude ambiguous characters' only when you will type the password yourself, so you do not mix up things like the letter O and the number 0.
Replace anything leaked
Make a fresh one for any password you reused, shared with someone, or saw turn up in a data leak. It only takes a few seconds here.
Why a Password Generator matters, in numbers
A few plain-English numbers that show why a longer password with a good mix of characters, like the ones this generator makes, is far safer than one you would think up yourself.
Hodiny
Is all it takes for a single ordinary computer to crack a short password of about 8 characters. It simply fires off millions of guesses a second until one matches. Short passwords just do not stand a chance any more.
Basically forever
Take that same short password and just make it twice as long. Now even every computer on earth working together could keep guessing until the sun burns out and still not get through. That one change, going from 8 characters to 16, is the difference between an afternoon and longer than the universe has existed.
65%
Of people, roughly 2 in 3, use the same password in more than one place. So when one website gets hacked, criminals quietly try that same password on your email, your bank, and everything else. A different password for each account stops that cold.
100x+
Harder to crack, just from mixing in capital letters, numbers, and symbols instead of using only lowercase. Every kind of character you add multiplies the guessing an attacker has to do, and it stacks up across the whole password. A good mix does what length alone cannot.
What a strong Password Generator gets right
A strong password comes down to four things. A good password generator handles every one of them for you, so you never have to weigh them up by hand.
Délka
Délka je nejdůležitější faktor. Každý přidaný znak násobí celkový počet možných kombinací. Přechod z 8 na 16 znaků prohledávaný prostor nezdvojnásobí, ale umocní ho na druhou.
Rozmanitost
Rozmanitost znaků násobí prohledávaný prostor. Kombinace malých písmen, velkých písmen, číslic a symbolů dramaticky rozšiřuje sadu znaků, kterou musí útočník prohledávat. Heslo tvořené pouze malými písmeny nabízí 26 možností na znak; přidáním všech čtyř typů se tento počet zvýší přibližně na 95.
Náhodnost
Předvídatelné vzory, jako jsou pohyby po klávesnici, jména následovaná rokem narození nebo oblíbené sportovní týmy, se objevují v každém útočném slovníku. Skutečná náhodnost generovaná kryptografickým zdrojem je imunní vůči slovníkovým a pravidlovým útokům.
Jedinečnost
Opakované použití hesla na více účtech znamená, že jeden únik odhalí všechny z nich. Každá služba by měla mít vlastní jedinečné heslo, aby byl případný kompromis vždy omezen na jediný účet.
Why use SecretNote's Password Generator
We do not just hand you a tool and walk away. We explain how passwords are cracked in plain language and show you the best-practice way to stay safe, even if you have no technical background at all.
What is brute-forcing?
Brute-forcing is easy to picture. Instead of knowing your password, an attacker points a computer at it and simply guesses, trying millions and millions of combinations one after another until one works. The computer never gets tired and it is fully automated, so the only things slowing it down are how hard your password is to guess and how quickly the website stops it from trying again and again. That is the whole reason a long, random password matters so much. That is exactly why password generators and password managers go hand in hand: one makes every password long and random, the other remembers them all, so each account gets its own and a single leak can never be reused anywhere else.
Where it happens
Mostly out of sight. Sometimes the guessing is aimed straight at a website's login page. More often it happens on a copy of a leaked password list that attackers have already downloaded, where they can guess as fast as their machines allow, completely offline and with no one watching.
How you stay safe
Use a long, random, one-of-a-kind password like the ones above, keep it in a password manager, and switch on two-factor login (a second code from your phone or an app) wherever it is offered. Even if one password is guessed or leaked, that second step and a different password everywhere else keep the damage tiny.
How good sites protect you
Responsible websites slow attackers down: they lock an account after a handful of wrong tries, add small delays between attempts, store passwords scrambled so a leak is not instantly readable, offer two-factor login, and block the floods of automated guesses that bots send.
Signs a site takes it seriously
Look for a web address that starts with https, the option to turn on two-factor login, and a sensible pause after a few wrong passwords. The bot check matters too: many popular ones such as reCAPTCHA and hCaptcha can be solved by cheap services for a fraction of a cent, so they barely slow a real attacker down. Newer privacy-friendly options like PrivCaptcha are a better sign.
Test a password
Type any password below to see a rough estimate of how long it would take to guess by brute force.
This runs entirely in your browser. What you type is never sent anywhere, never saved, and never leaves this page.
Password Alternative: Passkeys?
A password is only as safe as it is hard to guess. Passkeys take a different route: there is no secret to type, guess, or leak in the first place. Here is what that means in plain terms.
What is a passkey?
Instead of a password you remember, a unique key is created for each website and unlocked with your fingerprint, face, or device PIN. You never see or type a secret. The key can live on your phone or laptop, or inside a password manager such as 1Password, Bitwarden, or LastPass - in that case the manager creates and stores the passkey for you and syncs it to every device you sign into, so you are not tied to one phone or brand.
Why it is stronger
There is nothing to brute-force, nothing to reuse, and nothing to hand over to a fake login page. A passkey cannot be phished or guessed, and because it never leaves your device, a website being hacked does not expose it.
The catch, for now
The main limit is that not every website supports passkeys yet. Moving them between devices is easy if you store them in a password manager, and only gets fiddly if you keep them locked to a single phone or brand. So the honest advice is: use a passkey wherever it is offered, ideally through a manager, and for every site that does not support them yet keep using a long, generated password. The two work happily side by side.
Často kladené dotazy
Odpovědi na nejčastěji kladené otázky o bezpečnosti hesel.
More privacy tools
Everything you need to share private data safely - free, no account needed to get started, runs in your browser.
SecretNote
Write a private note, generate a one-time link, and share it. The note self-destructs the moment it is read - nothing is stored, nothing leaks.
Create a secret note →SecretScreen
Upload a screenshot and get a self-destructing share link. The image is encrypted before upload and deleted after the first view - no permanent hosting.
Share a screenshot →SecretFile
Upload any file and share a one-time download link. The file is encrypted end-to-end and permanently deleted after the recipient downloads it.
Send a secret file →Generátor hashů
Instantly generate MD5, SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512 hashes in your browser. Your input is never sent to the server.
Generate a hash →