05 · Password

Password generator with a built-in checker

Create a passphrase from Swedish words, or a password of random characters. Test a password and see whether it has leaked.

The password created:

Type of password
20 characters
  • Created and tested in your browser
  • Nothing is stored by us
  • The leak check sends only five characters of a checksum

How it works

How it goes

  1. You create

    Start with a passphrase of four Swedish words, or choose random characters if the service requires it. Everything is randomised by the browser on your own device.

  2. You test

    Type a password in the test field and get an estimate in bits, with concrete advice: is it built on a word, a year or a keyboard pattern?

  3. You check for leaks

    If you want to know whether the password has appeared in a leak, you press the button. The browser sends only five characters of a checksum, never the password itself.

Good to know about the method

  • The strength is a rough estimate. The tool recognises common words, years, keyboard patterns and repetitions and lowers the value for them, but it does not know all words. An unusual word can be easier to guess than the number shows. Its word lists are mainly Swedish: it knows Swedish words and names better than English ones.
  • The bits for a passphrase apply when the words are drawn at random from a list, as here. A phrase you make up yourself, for example a sentence you know by heart, is much weaker.
  • A strong password that is used on several services is still a risk. When one of the services leaks, the password is tried on all the others.
  • The leak check only knows about leaks that have been published. That a password is not found does not mean that it is safe.
  • The tool does not know what your particular service allows. Some services only accept certain characters or a maximum length.
  • Never type a password that you still use into a tool you do not trust. Here it stays in your browser: the randomisation and the analysis run locally, and the leak check sends only five characters of a checksum. If you want to be completely sure, test a password that is similar to the real one.
  • This page loads no statistics, no advertising script and no chat. Nothing but our own scripts runs where you type your password.

What is a strong password?

A strong password is long, random and used in one place only. Length counts for more than complicated characters: each extra character makes it harder to guess, while an “a” swapped for “@” hardly helps, because whoever is guessing knows the usual swaps. According to the guidelines from the American standards institute NIST, passwords should not be changed on a schedule without a particular reason. Change it when there is reason to believe that someone else knows it, for example after a leak.

Why a passphrase with Swedish words?

Six random words are easier to remember and type than ten or eleven random characters, especially on a phone, but about as hard to guess. The strength comes from the randomness and the number of words, not from the words themselves. This generator picks words from its own list of common Swedish words, and each word gives the same number of bits. A phrase that you make up yourself, such as a sentence from a book, is considerably weaker. If you want an extra margin, choose six words or more. The word list is Swedish only: if you want a password that is not in Swedish, choose random characters.

How do I know whether my password has leaked?

When a service is hacked, the passwords often end up on lists that are used to try logins at other services. The Pwned Passwords service collects published passwords, and our leak check asks it without giving out the password: the browser calculates a checksum, sends only the first five characters and compares the rest itself with the answer. If the password is found, change it everywhere you use it. If it is not found, that only means that it is not in the leaks that have been published.

What else should the company do?

A good password is not enough on its own. Use a unique password for each service and keep them in a password manager, not in a spreadsheet or on a note. Turn on two-step verification, especially for email, bookkeeping, web hosting and domain. Remove accounts when someone leaves and go through who has access to what. Also talk to the staff about fake emails, because many passwords are not guessed but given away by mistake.

Fixed packages

Do you want help with the routines?

It is usually the routines that fail, not the passwords. Prices include VAT, and the scope is confirmed in writing before we start.

Frequently asked questions

Questions about the password checker

Is my password sent to YourWeb?

No. The password you create or type is handled only in your browser. The only thing that can be sent is the first five characters of a SHA-1 checksum, and only when you yourself press the button for the leak check. The five characters are shared by over a thousand known passwords, so they do not point out yours. The password and the rest of the checksum never leave your device.

Is a passphrase really more secure?

It can be at least as hard to guess and is much easier to type and remember. Four random words from our list correspond to about seven random characters, and six words to about ten or eleven. It is the randomness that makes phrases secure, so a sentence you make up yourself does not count. If a service only allows short passwords, random characters are the better choice.

What do bits mean?

Bits measure how many guesses may be needed. A password with 44 bits could have been chosen in about 17.6 trillion ways, and each extra bit doubles the number. For passwords that the tool creates, the number is based on the randomness in how they were created. For a password that you type, it is a rough estimate.

What do I do if the password is in a leak?

Change it at once everywhere you use it, starting with email and bank. Choose a new password for each service, preferably one that you create here, and turn on two-step verification. A hit means that the password is on lists that attackers try. It does not mean that your account in particular has been hacked.

Do you want order in the company’s passwords?

Tell us how the company does it today, and we suggest what gives the most protection first. You get a written price before we start.

Chat with us