How SecurePass works

No server ever sees your passwords. You can check every part.

Made on your device

Every character comes from crypto.getRandomValues, the browser's cryptographic random generator.

Numbers that would make some characters likelier are thrown away, so every password is equally likely. Without secure randomness, nothing is generated.

The function every character passes through
export function randomInt(n: number): number {
  if (!Number.isSafeInteger(n) || n < 1 || n > UINT32_RANGE) {
    throw new RangeError(`randomInt needs an integer range between 1 and 2^32, got ${n}`);
  }
  const source = secureSource();
  // 2^32 is rarely a multiple of n, so reducing every draw modulo n would make the low results
  // slightly more likely. Draws at or above the largest multiple of n are discarded and redrawn;
  // even in the worst case under half of all draws are rejected, so the loop ends quickly.
  const limit = Math.floor(UINT32_RANGE / n) * n;
  const draw = new Uint32Array(1);
  for (;;) {
    source.getRandomValues(draw);
    const value = draw[0] ?? limit;
    if (value < limit) return value % n;
  }
}

Nothing is sent

Generating and checking make no network requests, and the security policy would block one. The counter tracks every request to another site.

Check it yourself

  1. Open developer tools (F12, or Cmd Option I on a Mac).
  2. Choose the Network tab.
  3. Generate and check passwords. The list stays empty.

Or turn on airplane mode: after one visit, it still works.

0

requests to other sites since you opened this page

Works offline after your first visit.

Locked down by your browser

A strict Content Security Policy stops the page loading outside scripts, sending data elsewhere, or being framed, even if its own code had a bug.

Here is the exact policy this page arrived with.

default-src 'none'
Block everything that is not explicitly allowed below.
script-src 'self' 'sha256-wzSTKVRzhp6995mnNaSiDXEUvxIxwPJxho/of/nQob0='
Only SecurePass's own scripts, plus one inline theme script pinned by its hash.
style-src 'self'
Load styles only from SecurePass. No inline styles.
img-src 'self'
Load images only from SecurePass.
font-src 'self'
Load fonts only from SecurePass. No font CDNs that could log your visit.
connect-src 'self' https://api.pwnedpasswords.com
Requests go only to SecurePass, and to the breach check when you ask.
manifest-src 'self'
Read the install manifest only from SecurePass.
worker-src 'self'
Run only SecurePass's own offline service worker.
base-uri 'none'
Stop injected markup from redirecting where relative links point.
form-action 'none'
Nothing on the page can submit a form anywhere.
frame-ancestors 'none'
No other site can embed SecurePass in a frame to trick you.
object-src 'none'
No plugins or embedded objects.
upgrade-insecure-requests
Any plain HTTP request is upgraded to HTTPS.
require-trusted-types-for 'script'
The page cannot turn text into code. Every script URL has to pass a reviewed policy.
trusted-types securepass
That policy exists for one job: registering the offline service worker at /sw.js.
The other security headers
Strict-Transport-Security
Browsers must use HTTPS for securepass.dev for the next two years.
Referrer-Policy
Never tell another site which page you came from.
X-Content-Type-Options
Browsers must not guess file types, so a file can't be passed off as a script.
X-Frame-Options
The older form of the frame ban, for browsers that predate frame-ancestors.
Cross-Origin-Opener-Policy
Other windows cannot keep a handle on this page.
Cross-Origin-Embedder-Policy
The page refuses resources from other sites unless they explicitly opt in.
Cross-Origin-Resource-Policy
Other sites cannot load SecurePass's files into their pages.
Permissions-Policy
Camera, microphone, location and 29 more are off. Only clipboard writing is allowed.

Nothing stored, nothing tracked

No accounts, cookies, analytics, ads or third-party scripts.

Only your settings are remembered, in this browser. Clearing site data removes them.

Remembered on this device

  • Length and character choices
  • Passphrase and PIN settings
  • Light or dark theme

Never kept anywhere

  • Generated passwords
  • Passwords you check
  • Breach check results
  • Your IP address, device or visits

A breach check that never sees your password

Have I Been Pwned holds hundreds of millions of leaked passwords. k-anonymity looks yours up without sending it, and only when you ask.

  1. Your device hashes the password with SHA-1.

    password 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8

  2. Only the first 5 of 40 characters are sent.

    api.pwnedpasswords.com/range/5BAA6

  3. Every leaked hash starting with those 5 comes back, padded with decoys.

    0018A45C4D1DEF81644B54AB7F969B88D65:count00D4F6E8FA6EECAD2A3AA415EEC418D38EC:count…1E4C9B93F3F0682250B6CF8331B7EE68FD8:count…

  4. Your device looks for the other 35. The service never learns which, if any, was yours.

    1E4C9B93F3F0682250B6CF8331B7EE68FD8 found

Data: Have I Been Pwned. No cookies or referrer are sent, and it is the only other site the policy allows.

How crack time is estimated

The headline assumes a well-equipped attacker, so it never flatters.

Generated: exact maths

Strength is the number of passwords your settings could produce, in bits: about 131 for 20 characters, 77.5 for six words. Time is half of those guesses at the attacker's speed.

Typed: pattern analysis

zxcvbn finds the words, names, dates, keyboard runs and substitutions cracking tools try first, and counts the guesses they take.

Attack speeds used for the estimates
AttackGuesses per secondAssumption
Online, rate-limited100 guesses per hourGuessing through a login page that slows down or locks out repeated attempts. This is zxcvbn's throttled-online assumption. Source
Online, no rate limit1,000 guesses per secondGuessing against a login or API that never slows the attacker down, which OWASP warns against. The service itself becomes the bottleneck. Source
Offline, slow hash100,000 guesses per secondA stolen database protected by a slow password hash (bcrypt, cost 10), attacked with twelve RTX 5090 graphics cards, as in Hive Systems' 2025 password table. Source
Offline, fast hash3 trillion guesses per secondA stolen database protected only by a fast hash such as MD5 or SHA-1, attacked with twelve RTX 5090 cards at about 220 billion MD5 guesses per second each (2.64 trillion in total), rounded up. Source

Ratings

  • Very weakunder 45 bits
  • Weak45 to 59 bits
  • Fair60 to 74 bits
  • Strong75 to 99 bits
  • Excellent100 bits or more

Password, passphrase or PIN

What makes a generated password strong

Length matters most. Twenty characters from all four sets give about 131 bits: longer than the universe has existed to guess, even at three trillion tries a second.

Use one per account, in a password manager. If a site rejects some symbols, leave them out rather than shortening it.

Password generator

Why random words work

Each word comes at random from the EFF's list of 7,776, adding about 12.9 bits. Six words give 77.5 bits; seven give 90.5.

Let the generator choose. Words people pick are the first ones cracking tools try.

Passphrase generator

When a PIN is enough

Six digits are only a million options, so use a PIN only where wrong guesses lock you out, like a phone or bank card.

Skip birthdays, repeats and patterns like 123456: they're tried first.

PIN generator

How the strength check works

zxcvbn, the estimator first built at Dropbox, runs in your browser. It finds the patterns cracking tools try first and counts the guesses they take.

Long, patternless runs count as random, so generated passwords get full credit and familiar ones don't.

Password strength checker

Good password habits

From NIST SP 800-63B-4 (2025).

  • Length beats complexity

    15 characters or more. Length and randomness count, not symbol rules.

  • One per account

    Reuse turns one breach into many. A password manager makes it easy.

  • Check for breaches

    Leaked passwords are the first ones attackers try.

  • Change when there's a reason

    Not on a schedule: when there's any sign of exposure.

  • Add a second factor

    Passkeys or two-factor sign-in make a stolen password useless on its own.