When I need a password for a new account, I don't try to come up with one anymore.
Because the passwords we create ourselves usually aren't as random as we think.
Something like:
MyProject@2026!
looks reasonable.
But it contains a word, a predictable number, and a familiar symbol pattern.
That's not really randomness.
So I built a simple password generator
The idea is straightforward: instead of asking someone to invent a password, let them generate one from a configurable character set.
The MahaVault Password Generator lets you choose:
- Password length from 6 to 64 characters
- Lowercase letters
- Uppercase letters
- Numbers
- Symbols
- Whether ambiguous characters should be excluded
For example, you can generate something like:
T7#mQ9!vL2@pK8$zR5
There is no name, date, word, or obvious pattern to remember.
Why character selection matters
The size of the character pool affects the number of possible combinations.
If you only use lowercase letters, the available character set is much smaller than if you combine lowercase, uppercase, numbers, and symbols.
Increasing the password length increases the search space as well.
That's why I prefer generating passwords rather than trying to make an existing word "stronger" by adding a number and a symbol.
What about ambiguous characters?
There are situations where a generated password needs to be typed manually.
Characters such as:
0 O
1 l I
can easily be confused.
The generator has an option to exclude ambiguous characters when needed.
If the password is going straight into a password manager, this option may not matter much. But for passwords that someone needs to read or type, it can be useful.
A little more information than just the password
The generator also shows information about the generated password, including:
- Entropy
- Character pool
- Password length
- Estimated offline crack time
That makes it easier to understand what you're actually generating instead of simply seeing a random-looking string and assuming it's strong.
One password per account
Of course, generating a strong password is only part of the problem.
Don't reuse the same password across multiple services.
If one service gets compromised and that password is reused elsewhere, the problem suddenly becomes much bigger.
Generate a unique password for each account and store those passwords in a password manager.
Try it
I built the Password Generator as part of the MahaVault developer and security tools:
https://www.mahavault.com/tools/password-generator
Sometimes the easiest way to get a better password is simply to stop trying to invent one.
Top comments (0)