one job: generate your password
Locked. generates strong, random passwords using your browser's cryptographically secure random number generator, not a predictable pseudo-random function. Choose a length and which character types to include, and get a fresh password instantly, along with a rough strength estimate.
It also has a Passphrase mode for sites and situations where a memorable, typeable password matters more than a random string, combining several random dictionary words the way "correct horse battery staple"-style passphrases work, optionally with a number or symbol added.
It's built for the moment a site demands "a new password" and you don't want to reuse one or make one up on the spot. Nothing is sent anywhere, generation happens entirely on your device.
Yes. Passwords are generated using the browser's cryptographically secure random number generator, not a predictable pseudo-random function, and everything happens locally without being sent to a server.
At least 12 characters is a reasonable minimum today, with 16 or more recommended for anything sensitive. Longer passwords are exponentially harder to crack than adding more character types.
Yes, where the site allows it. Mixing uppercase, lowercase, numbers, and symbols increases the pool of possible characters, which increases the number of guesses an attacker needs.
No. Generation happens entirely in your browser using JavaScript. Nothing is transmitted, logged, or saved.
A passphrase strings together several random dictionary words instead of random characters, for example "Rocket-Tulip-Anchor-42". It's easier to type and remember than a random character string while still being hard to guess, since each added word multiplies the number of possible combinations.