Your passwords never leave the browser
The generator runs entirely on your device and takes its randomness from the browser’s cryptographic generator (crypto.getRandomValues). Passwords are never sent to a server, stored or logged.
What makes a strong password
- Long. Every extra character makes guessing dozens of times harder. Use at least 14 characters for accounts and 20 for servers and databases.
- Random. Words, dates and letters swapped for digits (“P@ssw0rd”) are the first things dictionary attacks try.
- Unique. Use a separate password for every service, so a leak from one site doesn’t expose the others.
Entropy shows how many combinations an attacker would have to try: 72 bits or more is considered resistant to brute force even on powerful hardware. Keep your passwords in a password manager and turn on two-factor authentication wherever it’s available — including in your MEVCORE client area.