SecretNote.eu

Passwort-Generator - create strong random passwords in your browser

Password Generator Workspace

Passe die Einstellungen unten an und generiere so viele Passwörter, wie du brauchst.

Stark Geschätzte Entropie: 128 Bit
18
24

Password Generator Quick Guidance

A short checklist for getting the strongest result out of the generator above.

Make it long

Go for at least 16 characters, and longer whenever a site lets you. Length is the single best thing you can do to keep a password safe.

Let it be generated

Do not make one up in your head. Anything that is easy for you to remember is usually already on a hacker's list of common guesses.

Save it in a manager

Keep it in a password manager such as Bitwarden, 1Password, KeePass, or LastPass. Then you never have to remember it, and every account can have a different one.

Mix the characters

Leave at least three of the four switches on: small letters, capital letters, numbers, and symbols. The more variety, the harder it is to guess.

Skip look-alikes only by hand

Turn on 'exclude ambiguous characters' only when you will type the password yourself, so you do not mix up things like the letter O and the number 0.

Replace anything leaked

Make a fresh one for any password you reused, shared with someone, or saw turn up in a data leak. It only takes a few seconds here.

Why a Password Generator matters, in numbers

A few plain-English numbers that show why a longer password with a good mix of characters, like the ones this generator makes, is far safer than one you would think up yourself.

Stunden

Is all it takes for a single ordinary computer to crack a short password of about 8 characters. It simply fires off millions of guesses a second until one matches. Short passwords just do not stand a chance any more.

Basically forever

Take that same short password and just make it twice as long. Now even every computer on earth working together could keep guessing until the sun burns out and still not get through. That one change, going from 8 characters to 16, is the difference between an afternoon and longer than the universe has existed.

65%

Of people, roughly 2 in 3, use the same password in more than one place. So when one website gets hacked, criminals quietly try that same password on your email, your bank, and everything else. A different password for each account stops that cold.

100x+

Harder to crack, just from mixing in capital letters, numbers, and symbols instead of using only lowercase. Every kind of character you add multiplies the guessing an attacker has to do, and it stacks up across the whole password. A good mix does what length alone cannot.

What a strong Password Generator gets right

A strong password comes down to four things. A good password generator handles every one of them for you, so you never have to weigh them up by hand.

Länge

Länge ist der wichtigste Einzelfaktor. Jedes zusätzliche Zeichen multipliziert die Gesamtzahl möglicher Kombinationen. Der Wechsel von 8 auf 16 Zeichen verdoppelt den Suchraum nicht, er quadriert ihn.

Vielfalt

Zeichenvielfalt multipliziert den Suchraum. Die Kombination aus Kleinbuchstaben, Großbuchstaben, Ziffern und Sonderzeichen erweitert den Zeichensatz, den ein Angreifer durchsuchen muss, erheblich. Ein Passwort, das nur aus Kleinbuchstaben besteht, hat 26 Möglichkeiten pro Zeichen; werden alle vier Typen hinzugefügt, steigt diese Zahl auf etwa 95.

Zufälligkeit

Vorhersehbare Muster, wie Tastatur-Sequenzen, Namen gefolgt von einem Geburtsjahr oder Lieblingssportteams, tauchen in jedem Angriffswörterbuch auf. Echte Zufälligkeit, erzeugt von einer kryptografischen Quelle, ist gegen Wörterbuch- und regelbasierte Angriffe immun.

Einzigartigkeit

Wer ein Passwort für mehrere Konten wiederverwendet, riskiert, dass ein einziges Datenleck alle davon kompromittiert. Jeder Dienst sollte ein eigenes, einzigartiges Passwort haben, damit ein Sicherheitsvorfall stets auf ein einziges Konto begrenzt bleibt.

Why use SecretNote's Password Generator

We do not just hand you a tool and walk away. We explain how passwords are cracked in plain language and show you the best-practice way to stay safe, even if you have no technical background at all.

SecretNote Typical online tool
Passwords are generated in your browser and never sent anywhere
Length, character mix, and a live strength read-out in one place
Explained in plain language for non-technical people
Shows the best-practice habits: managers, unique passwords, 2FA
No account, no sign-up, no ads tracking you, always free

What is brute-forcing?

Brute-forcing is easy to picture. Instead of knowing your password, an attacker points a computer at it and simply guesses, trying millions and millions of combinations one after another until one works. The computer never gets tired and it is fully automated, so the only things slowing it down are how hard your password is to guess and how quickly the website stops it from trying again and again. That is the whole reason a long, random password matters so much. That is exactly why password generators and password managers go hand in hand: one makes every password long and random, the other remembers them all, so each account gets its own and a single leak can never be reused anywhere else.

Where it happens

Mostly out of sight. Sometimes the guessing is aimed straight at a website's login page. More often it happens on a copy of a leaked password list that attackers have already downloaded, where they can guess as fast as their machines allow, completely offline and with no one watching.

How you stay safe

Use a long, random, one-of-a-kind password like the ones above, keep it in a password manager, and switch on two-factor login (a second code from your phone or an app) wherever it is offered. Even if one password is guessed or leaked, that second step and a different password everywhere else keep the damage tiny.

How good sites protect you

Responsible websites slow attackers down: they lock an account after a handful of wrong tries, add small delays between attempts, store passwords scrambled so a leak is not instantly readable, offer two-factor login, and block the floods of automated guesses that bots send.

Signs a site takes it seriously

Look for a web address that starts with https, the option to turn on two-factor login, and a sensible pause after a few wrong passwords. The bot check matters too: many popular ones such as reCAPTCHA and hCaptcha can be solved by cheap services for a fraction of a cent, so they barely slow a real attacker down. Newer privacy-friendly options like PrivCaptcha are a better sign.

Test a password

Type any password below to see a rough estimate of how long it would take to guess by brute force.

Estimated time to guess

This runs entirely in your browser. What you type is never sent anywhere, never saved, and never leaves this page.

Password Alternative: Passkeys?

A password is only as safe as it is hard to guess. Passkeys take a different route: there is no secret to type, guess, or leak in the first place. Here is what that means in plain terms.

What is a passkey?

Instead of a password you remember, a unique key is created for each website and unlocked with your fingerprint, face, or device PIN. You never see or type a secret. The key can live on your phone or laptop, or inside a password manager such as 1Password, Bitwarden, or LastPass - in that case the manager creates and stores the passkey for you and syncs it to every device you sign into, so you are not tied to one phone or brand.

Why it is stronger

There is nothing to brute-force, nothing to reuse, and nothing to hand over to a fake login page. A passkey cannot be phished or guessed, and because it never leaves your device, a website being hacked does not expose it.

The catch, for now

The main limit is that not every website supports passkeys yet. Moving them between devices is easy if you store them in a password manager, and only gets fiddly if you keep them locked to a single phone or brand. So the honest advice is: use a passkey wherever it is offered, ideally through a manager, and for every site that does not support them yet keep using a long, generated password. The two work happily side by side.

häufig gefragt

Häufig gestellte Fragen

Antworten auf die häufigsten Fragen rund um Passwortsicherheit.

Passwort-Entropie ist ein Maß für Unvorhersehbarkeit, ausgedrückt in Bit. Jedes Bit verdoppelt die Anzahl der Versuche, die ein Angreifer im Durchschnitt benötigt: 64 Bit erfordern 2^64 Versuche, 128 Bit erfordern 2^128. Die genaue Entropie eines zufällig generierten Passworts ergibt sich aus log2(Zeichensatzgröße) multipliziert mit der Passwortlänge. Ein 16-Zeichen-Passwort aus einem 95-Zeichen-Satz hat 16 x log2(95) = 105 Bit. Alles über 75 Bit gilt mit aktueller GPU-Hardware als sicher gegen Offline-Brute-Force-Angriffe; 128 Bit sind mit jeder absehbaren Rechentechnologie unknackbar, einschließlich Quantencomputern, die Grovers Algorithmus ausführen.
Angreifer führen Wörterbuchangriffe durch, bei denen Millionen gängiger Wörter, Phrasen und vorhersehbarer Transformationen (Großschreibung, Leet-Ersetzungen wie „a" zu „@", Anhängen von Ziffern oder Jahreszahlen) getestet werden, bevor Brute Force zum Einsatz kommt. Jedes Passwort, das sich ein Mensch leicht merken kann, darunter Phrasen, Namen, Daten oder Sportteams, taucht in Cracking-Wörterbüchern (rockyou.txt, HaveIBeenPwned, benutzerdefinierte Korpus-Dumps) meist innerhalb der ersten paar Millionen Versuche auf. Ein 16-Zeichen-Zufallspasswort aus einem 95-Zeichen-Satz dauert etwa 4 Billiarden Mal länger zu erraten als ein typisches 8-Zeichen-Wort mit einer Ziffer am Ende. Die Lösung: Passwörter generieren, nicht erfinden.
Yes. A password manager (Bitwarden, 1Password, KeePass, Proton Pass, LastPass, or Apple Passwords) lets you use a unique, randomly generated password for every account without memorising any of them - you only remember one strong master password. The vault is encrypted locally with your master password, then optionally synced through the provider. The alternative - reusing the same password across sites or storing them in a text file or browser autofill without encryption - means a single breach exposes every account. Modern managers also generate passkeys, monitor breach databases, and warn you about reused or weak entries.
Ändere Passwörter nicht nach einem festen Zeitplan. NIST SP 800-63B (2017, in nachfolgenden Überarbeitungen bestätigt) empfiehlt ausdrücklich, auf eine obligatorische regelmäßige Rotation zu verzichten, da sie Nutzer zu vorhersehbaren Mustern verleitet. Das Ändern von „Sommer2024!" zu „Sommer2025!" schwächt die Sicherheit, anstatt sie zu verbessern. Ändere ein Passwort nur bei einem konkreten Anlass: einem bestätigten Datenleck (HaveIBeenPwned-Benachrichtigung, Anbietermeldung), einem gemeinsamen Zugang, der widerrufen werden muss, dem Verdacht auf Phishing oder Gerätekompromittierung oder nach der Nutzung auf einem nicht vertrauenswürdigen Gerät. Mit einem Passwort-Manager und einem einzigartigen Zufallspasswort pro Website bleibt die Auswirkung eines Datenlecks auf das betroffene Konto beschränkt.
Vier Eigenschaften zusammen: Länge, Zufälligkeit, Zeichenvielfalt und Einzigartigkeit. Länge ist am wichtigsten, denn jedes zusätzliche Zeichen aus einem 95-Zeichen-Satz multipliziert die Anzahl der Versuche mit 95. Zufälligkeit schließt Wörterbuchangriffe aus. Vielfalt (Kleinbuchstaben, Großbuchstaben, Ziffern, Sonderzeichen) maximiert den Suchraum pro Zeichen. Einzigartigkeit stellt sicher, dass ein Datenleck nicht auf andere Konten übergreift. Ein 16-Zeichen-Passwort, das von einer kryptografisch sicheren Zufallsquelle aus allen vier Zeichenklassen generiert wurde, hat etwa 105 Bit Entropie und ist derzeit durch Brute Force unknackbar.
Zwölf Zeichen sind das praktische Minimum, sechzehn oder mehr werden empfohlen, und zwanzig oder mehr sind für besonders wichtige Konten (E-Mail, Finanzen, Passwort-Manager-Master) bevorzugt. Bei einem Zeichensatz von 95 Zeichen pro Stelle liefern 12 Zeichen 79 Bit Entropie, 16 Zeichen 105 Bit und 20 Zeichen 131 Bit. Länge ist die günstigste Entropie, die man gewinnen kann, denn jedes zusätzliche Zeichen multipliziert den Aufwand des Angreifers, während Sonderzeichen und Groß-/Kleinschreibung nur marginal hinzufügen. Wenn ein System Passwörter auf 12 bis 16 Zeichen begrenzt, wähle die maximal erlaubte Länge und verwende einen Generator.
First, what is a passphrase? It is simply a password made of several random words strung together - like 'correct-horse-battery-staple' - instead of a jumble of letters, digits, and symbols. The appeal is that words are far easier for a human to remember and type than something like 'x7$Kp2!qLm'. Are they more secure? Only if they are long enough. A four-word passphrase from the EFF wordlist (7,776 words) gives 51 bits of entropy - weaker than a 9-character random password. Six words gives 77 bits, which is roughly equivalent to 12 random characters. Passphrases trade entropy density for memorability, so they need more words to reach the same strength as a random password. The sweet spot: use a long passphrase for the one password you must memorise (your device login or password manager master password), and let a generator make random passwords for everything else, since the manager remembers those for you.
Nein. Dieser Generator läuft vollständig in deinem Browser über die WebCrypto-API (window.crypto.getRandomValues), eine kryptografisch sichere Zufallsquelle, die vom Betriebssystem bereitgestellt wird. Das generierte Passwort wird lokal erstellt, nur dir angezeigt und nirgendwo übertragen. Der Server liefert die Seiteninhalte und hat keinen Einblick in das, was generiert wurde. Das macht das Tool sicher, auch für produktive Konten.
Where a website offers passkeys, yes - they are the more secure option. A passkey replaces the password entirely: instead of a secret you type, your phone or laptop creates a unique key per site and unlocks it with your fingerprint, face, or device PIN. Because there is nothing to type, reuse, or hand to a fake login page, a passkey cannot be phished, guessed, or brute-forced, and it never leaves your device, so a site being breached does not expose it. The catch is that support is still growing and moving passkeys between devices depends on your phone or browser ecosystem. The practical approach is to use passkeys wherever they are available and keep a long, generated password in a password manager for every site that does not support them yet. The two complement each other rather than compete.

More privacy tools

Everything you need to share private data safely - free, no account needed to get started, runs in your browser.