SecretNote.eu

Générateur de mots de passe - create strong random passwords in your browser

Password Generator Workspace

Ajuste les paramètres ci-dessous et génère autant de mots de passe que nécessaire.

Fort Entropie estimée à 128 bits
18
24

Password Generator Quick Guidance

A short checklist for getting the strongest result out of the generator above.

Make it long

Go for at least 16 characters, and longer whenever a site lets you. Length is the single best thing you can do to keep a password safe.

Let it be generated

Do not make one up in your head. Anything that is easy for you to remember is usually already on a hacker's list of common guesses.

Save it in a manager

Keep it in a password manager such as Bitwarden, 1Password, KeePass, or LastPass. Then you never have to remember it, and every account can have a different one.

Mix the characters

Leave at least three of the four switches on: small letters, capital letters, numbers, and symbols. The more variety, the harder it is to guess.

Skip look-alikes only by hand

Turn on 'exclude ambiguous characters' only when you will type the password yourself, so you do not mix up things like the letter O and the number 0.

Replace anything leaked

Make a fresh one for any password you reused, shared with someone, or saw turn up in a data leak. It only takes a few seconds here.

Why a Password Generator matters, in numbers

A few plain-English numbers that show why a longer password with a good mix of characters, like the ones this generator makes, is far safer than one you would think up yourself.

Heures

Is all it takes for a single ordinary computer to crack a short password of about 8 characters. It simply fires off millions of guesses a second until one matches. Short passwords just do not stand a chance any more.

Basically forever

Take that same short password and just make it twice as long. Now even every computer on earth working together could keep guessing until the sun burns out and still not get through. That one change, going from 8 characters to 16, is the difference between an afternoon and longer than the universe has existed.

65%

Of people, roughly 2 in 3, use the same password in more than one place. So when one website gets hacked, criminals quietly try that same password on your email, your bank, and everything else. A different password for each account stops that cold.

100x+

Harder to crack, just from mixing in capital letters, numbers, and symbols instead of using only lowercase. Every kind of character you add multiplies the guessing an attacker has to do, and it stacks up across the whole password. A good mix does what length alone cannot.

What a strong Password Generator gets right

A strong password comes down to four things. A good password generator handles every one of them for you, so you never have to weigh them up by hand.

Longueur

La longueur est le facteur le plus important. Chaque caractère supplémentaire multiplie le nombre total de combinaisons possibles. Passer de 8 à 16 caractères ne double pas l'espace de recherche : il le met au carré.

Variété

La variété de caractères multiplie l'espace de recherche. Mélanger minuscules, majuscules, chiffres et symboles élargit considérablement l'ensemble de caractères qu'un attaquant doit parcourir. Un mot de passe limité aux lettres minuscules offre 26 possibilités par caractère ; en ajoutant les quatre types, on passe à environ 95.

Aléatoire

Les schémas prévisibles, comme les suites de touches, les prénoms suivis d'une année de naissance ou les équipes sportives favorites, figurent dans tous les dictionnaires d'attaque. Le vrai aléatoire, généré par une source cryptographique, est insensible aux attaques par dictionnaire et aux attaques basées sur des règles.

Unicité

Réutiliser un mot de passe sur plusieurs comptes signifie qu'une seule fuite expose tous les autres. Chaque service doit avoir son propre mot de passe distinct, afin qu'une compromission reste toujours limitée à un seul compte.

Why use SecretNote's Password Generator

We do not just hand you a tool and walk away. We explain how passwords are cracked in plain language and show you the best-practice way to stay safe, even if you have no technical background at all.

SecretNote Typical online tool
Passwords are generated in your browser and never sent anywhere
Length, character mix, and a live strength read-out in one place
Explained in plain language for non-technical people
Shows the best-practice habits: managers, unique passwords, 2FA
No account, no sign-up, no ads tracking you, always free

What is brute-forcing?

Brute-forcing is easy to picture. Instead of knowing your password, an attacker points a computer at it and simply guesses, trying millions and millions of combinations one after another until one works. The computer never gets tired and it is fully automated, so the only things slowing it down are how hard your password is to guess and how quickly the website stops it from trying again and again. That is the whole reason a long, random password matters so much. That is exactly why password generators and password managers go hand in hand: one makes every password long and random, the other remembers them all, so each account gets its own and a single leak can never be reused anywhere else.

Where it happens

Mostly out of sight. Sometimes the guessing is aimed straight at a website's login page. More often it happens on a copy of a leaked password list that attackers have already downloaded, where they can guess as fast as their machines allow, completely offline and with no one watching.

How you stay safe

Use a long, random, one-of-a-kind password like the ones above, keep it in a password manager, and switch on two-factor login (a second code from your phone or an app) wherever it is offered. Even if one password is guessed or leaked, that second step and a different password everywhere else keep the damage tiny.

How good sites protect you

Responsible websites slow attackers down: they lock an account after a handful of wrong tries, add small delays between attempts, store passwords scrambled so a leak is not instantly readable, offer two-factor login, and block the floods of automated guesses that bots send.

Signs a site takes it seriously

Look for a web address that starts with https, the option to turn on two-factor login, and a sensible pause after a few wrong passwords. The bot check matters too: many popular ones such as reCAPTCHA and hCaptcha can be solved by cheap services for a fraction of a cent, so they barely slow a real attacker down. Newer privacy-friendly options like PrivCaptcha are a better sign.

Test a password

Type any password below to see a rough estimate of how long it would take to guess by brute force.

Estimated time to guess

This runs entirely in your browser. What you type is never sent anywhere, never saved, and never leaves this page.

Password Alternative: Passkeys?

A password is only as safe as it is hard to guess. Passkeys take a different route: there is no secret to type, guess, or leak in the first place. Here is what that means in plain terms.

What is a passkey?

Instead of a password you remember, a unique key is created for each website and unlocked with your fingerprint, face, or device PIN. You never see or type a secret. The key can live on your phone or laptop, or inside a password manager such as 1Password, Bitwarden, or LastPass - in that case the manager creates and stores the passkey for you and syncs it to every device you sign into, so you are not tied to one phone or brand.

Why it is stronger

There is nothing to brute-force, nothing to reuse, and nothing to hand over to a fake login page. A passkey cannot be phished or guessed, and because it never leaves your device, a website being hacked does not expose it.

The catch, for now

The main limit is that not every website supports passkeys yet. Moving them between devices is easy if you store them in a password manager, and only gets fiddly if you keep them locked to a single phone or brand. So the honest advice is: use a passkey wherever it is offered, ideally through a manager, and for every site that does not support them yet keep using a long, generated password. The two work happily side by side.

questions fréquentes

Foire aux questions

Réponses aux questions les plus fréquentes sur la sécurité des mots de passe.

L'entropie d'un mot de passe mesure son imprévisibilité, exprimée en bits. Chaque bit double le nombre de tentatives qu'un attaquant doit effectuer en moyenne : 64 bits nécessitent 2^64 tentatives et 128 bits en nécessitent 2^128. L'entropie exacte d'un mot de passe généré aléatoirement est égale à log2(taille_du_jeu_de_caractères) multiplié par la longueur du mot de passe. Un mot de passe de 16 caractères tiré d'un jeu de 95 caractères a 16 x log2(95) = 105 bits. Tout ce qui dépasse 75 bits est considéré comme sûr contre les attaques par force brute hors ligne avec le matériel GPU actuel ; 128 bits est incassable avec toute technologie informatique prévisible, y compris les ordinateurs quantiques exécutant l'algorithme de Grover.
Les attaquants lancent des attaques par dictionnaire qui testent des millions de mots courants, de phrases et de transformations prévisibles (mise en majuscules, substitutions leet comme « a » en « @ », ajout de chiffres ou d'années) avant de tenter la force brute. Tout mot de passe qu'un humain peut facilement mémoriser, y compris les phrases, les prénoms, les dates ou les équipes sportives, figure généralement dans les dictionnaires de craquage (rockyou.txt, HaveIBeenPwned, corpus personnalisés) dès les premiers millions de tentatives. Un mot de passe aléatoire de 16 caractères tiré d'un jeu de 95 caractères prend environ 4 quadrillions de fois plus de temps à deviner qu'un mot typique de 8 caractères avec un chiffre en suffixe. La solution : génère ton mot de passe, ne l'invente pas.
Yes. A password manager (Bitwarden, 1Password, KeePass, Proton Pass, LastPass, or Apple Passwords) lets you use a unique, randomly generated password for every account without memorising any of them - you only remember one strong master password. The vault is encrypted locally with your master password, then optionally synced through the provider. The alternative - reusing the same password across sites or storing them in a text file or browser autofill without encryption - means a single breach exposes every account. Modern managers also generate passkeys, monitor breach databases, and warn you about reused or weak entries.
Ne change pas tes mots de passe selon un calendrier fixe. Le NIST SP 800-63B (2017, confirmé dans les révisions ultérieures) déconseille explicitement la rotation périodique obligatoire, car elle pousse les utilisateurs vers des schémas prévisibles : remplacer « Summer2024! » par « Summer2025! » affaiblit la sécurité au lieu de l'améliorer. Change un mot de passe uniquement en cas de raison concrète : une fuite confirmée (alerte HaveIBeenPwned, notification du fournisseur), un accès partagé à révoquer, un soupçon de hameçonnage ou de compromission d'appareil, ou encore une exposition sur un appareil non fiable. Avec un gestionnaire de mots de passe et un mot de passe aléatoire unique par site, l'impact d'une fuite reste limité au seul compte concerné.
Quatre propriétés combinées : longueur, aléatoire, variété de caractères et unicité. La longueur est la plus importante : chaque caractère supplémentaire tiré d'un jeu de 95 caractères multiplie les tentatives par 95. L'aléatoire élimine les attaques par dictionnaire. La variété (minuscules, majuscules, chiffres, symboles) maximise l'espace de recherche par caractère. L'unicité garantit qu'une fuite ne se propage pas aux autres comptes. Un mot de passe de 16 caractères généré par une source aléatoire cryptographiquement sûre à partir des quatre classes de caractères offre environ 105 bits d'entropie et est actuellement incassable par force brute.
Douze caractères est le minimum pratique, seize ou plus est recommandé, et vingt ou plus est préférable pour les comptes à haute valeur (e-mail, finances, gestionnaire de mots de passe). Avec 95 caractères par position, 12 caractères donnent 79 bits d'entropie, 16 en donnent 105, et 20 en donnent 131. La longueur est l'entropie la moins coûteuse que tu puisses obtenir, car chaque caractère supplémentaire multiplie le travail de l'attaquant, tandis que la complexité des symboles et de la casse n'apporte qu'un gain marginal. Si un système limite les mots de passe à 12-16 caractères, préfère le maximum autorisé et utilise un générateur.
First, what is a passphrase? It is simply a password made of several random words strung together - like 'correct-horse-battery-staple' - instead of a jumble of letters, digits, and symbols. The appeal is that words are far easier for a human to remember and type than something like 'x7$Kp2!qLm'. Are they more secure? Only if they are long enough. A four-word passphrase from the EFF wordlist (7,776 words) gives 51 bits of entropy - weaker than a 9-character random password. Six words gives 77 bits, which is roughly equivalent to 12 random characters. Passphrases trade entropy density for memorability, so they need more words to reach the same strength as a random password. The sweet spot: use a long passphrase for the one password you must memorise (your device login or password manager master password), and let a generator make random passwords for everything else, since the manager remembers those for you.
Non. Ce générateur fonctionne entièrement dans ton navigateur via l'API WebCrypto (window.crypto.getRandomValues), une source d'aléatoire cryptographiquement sûre reposant sur le système d'exploitation. Le mot de passe généré est créé localement, affiché uniquement pour toi et jamais transmis nulle part. Le serveur fournit les ressources de la page et n'a aucune visibilité sur ce qui a été généré. Cela rend l'outil sûr à utiliser même pour des comptes en production.
Where a website offers passkeys, yes - they are the more secure option. A passkey replaces the password entirely: instead of a secret you type, your phone or laptop creates a unique key per site and unlocks it with your fingerprint, face, or device PIN. Because there is nothing to type, reuse, or hand to a fake login page, a passkey cannot be phished, guessed, or brute-forced, and it never leaves your device, so a site being breached does not expose it. The catch is that support is still growing and moving passkeys between devices depends on your phone or browser ecosystem. The practical approach is to use passkeys wherever they are available and keep a long, generated password in a password manager for every site that does not support them yet. The two complement each other rather than compete.

More privacy tools

Everything you need to share private data safely - free, no account needed to get started, runs in your browser.