How it works
AleaPass is a password generator with nothing to hide, so this page explains everything: where the randomness comes from, why no password can leave your device, how “strength” is computed, and how you can check each claim yourself.
The path of a password
- Operating system random source. Every modern OS keeps a pool of randomness fed by hardware noise (timing jitter, hardware generators such as RDRAND or a Secure Enclave). It is the same source your bank's app and your VPN use for their keys.
crypto.getRandomValues(). The browser exposes that pool through the Web Crypto API. The site asks it for 32-bit numbers, 64 at a time. This is a cryptographically secure generator;Math.random(), which many generators use, is not.- Rejection sampling. A 32-bit number must become a position in a list of, say, 89 characters. Taking the remainder of a division would favour the first few characters very slightly. Instead, the largest multiple of 89 below 232 is computed and any draw above it is thrown away and redrawn. Every character then has exactly the same probability.
- Character set or word list. Each position is filled independently from the alphabet you selected, or from one of the two 7,776-word lists. With “use at least one of each type” on, a candidate that misses a type is discarded whole and a new one is drawn, which keeps the distribution uniform.
- Password on screen, nowhere else. The result is written into the page and, when you ask, into your clipboard. It is never stored, never put in the URL, never sent.
- The server delivers static files, once. nginx serves a few HTML, CSS and JavaScript files over HTTPS with a strict Content-Security-Policy that forbids any third-party script, style, font or connection. Once loaded, the page has no reason to talk to the server again, and the policy would block it if it tried to talk to anyone else.
- Nothing goes back. No form is submitted, no analytics beacon is fired, no cookie is set, no local storage is used, and the server keeps no access log. There is simply no channel through which a password could leave your device.
How strength is measured
Because every password here is truly random, its strength does not depend on how it looks but on how many equally likely passwords the generator could have produced. That number is expressed in bits of entropy: a password with n bits is one of 2n possibilities.
- Random characters:
bits = length × log2(alphabet size). With all four types selected the alphabet has 89 characters, so each character adds about 6.5 bits. - Passphrases:
bits = words × log2(7,776) ≈ words × 12.9. The separator and capitalisation add nothing because they are not random; the optional digit adds a little. - When “use at least one of each type” is on, the exact number of qualifying passwords is counted (inclusion–exclusion) rather than estimated, so the displayed figure is precise. The constraint costs a fraction of a bit on long passwords and more on short ones.
| Secret | Entropy | Average time to crack at 1010 guesses/s |
|---|---|---|
| 6-digit PIN | 19.9 bits | instantly |
| 8 random characters, all types | 51.8 bits | a few days |
| 12 random characters, all types | 77.7 bits | hundreds of thousands of years |
| 5-word passphrase | 64.6 bits | about 50 years |
| 6-word passphrase | 77.5 bits | hundreds of thousands of years |
| 16 random characters, all types | 103.6 bits | longer than the age of the universe |
| 20 random characters, all types | 129.5 bits | longer than the age of the universe |
The time estimate assumes an offline attacker who has stolen a database of password hashes and tries ten billion candidates per second, which is what a rack of graphics cards achieves against a fast hash such as MD5 or NTLM. Against a slow hash (bcrypt, scrypt, Argon2) the same hardware is thousands of times slower, and an online attack against a login form is slower still because the service throttles attempts. The figure is deliberately pessimistic.
Rules of thumb: 40 bits stops casual attackers, 60 bits is comfortable for an account protected by a slow hash, 80 bits and above is safe against anyone for the foreseeable future, and 128 bits is what cryptographers call “computationally infeasible”. Anything you store in a password manager may as well be 20 characters or more, since you never type it.
Passwords or passphrases?
A passphrase such as ripple-basket-pilot-cinema-onion-fossil is easier to read aloud, to type on a phone and to remember than x7$Kq!2pLm#9, and six words already give 77 bits. Use passphrases for the few secrets you must type or memorise: your password manager's master password, your computer login, disk encryption. Use random characters for everything the manager stores for you.
The word lists
Both lists contain exactly 7,776 = 65 words, which is the size used by the Diceware method: number the words from 11111 to 66666 and you can pick them by rolling five dice, with no computer involved at all. The lists are available as plain text in that format: en.txt and fr.txt.
- English: the EFF long word list (2016), a carefully curated list of common, distinct, easy-to-spell words. © Electronic Frontier Foundation, CC BY 3.0.
- French: a list built for this site from the most frequent French words (frequency data from the wordfreq project), keeping only dictionary words of 4 to 8 letters, with accents removed so that every word can be typed on any keyboard, inflected duplicates merged and offensive or awkward words filtered out. CC BY-SA 4.0.
What this site does not do
- No account, no form, no server-side code: the server only hands out files.
- No cookies, no local storage, no session storage, no fingerprinting.
- No analytics, no advertising, no third-party script, font, image or connection. The Content-Security-Policy makes this a technical impossibility, not a promise.
- No access logs on the server (see the privacy policy).
- Your settings (length, character types…) and the terminal look are kept in the address bar after the
#sign so that you can bookmark them. Browsers never send that part of the address to any server, and the generated password is never put there.
Security headers
Every response from the server carries the headers below. You can see them with curl -I https://aleapass.com or with an online checker such as the Mozilla HTTP Observatory.
Content-Security-Policydefault-src 'none'; script-src 'self'; style-src 'self'; img-src 'self'; manifest-src 'self'; worker-src 'self'; connect-src 'none'; base-uri 'none'; form-action 'none'; frame-ancestors 'none'— only the site's own scripts and styles may run, no inline code, no network connections from the page, and the page cannot be embedded in another site. (The service-worker script gets its own, equally strict policy that only allows it to fetch the site's own files for the offline cache.)Strict-Transport-Security- browsers must use HTTPS for two years, including for subdomains.
Referrer-Policy: no-referrer- if you follow a link from here, the destination is not told where you came from.
Permissions-Policy- camera, microphone, geolocation, payment, USB and the advertising-related Topics API are all switched off for this origin.
X-Content-Type-Options: nosniff,X-Frame-Options: DENY,Cross-Origin-Opener-Policy,Cross-Origin-Resource-Policy- defence-in-depth against content sniffing, clickjacking and cross-origin leaks.
Offline and installable
A small service worker stores the site's own files in your browser the first time you visit, so the generator keeps working without a network connection and can be installed as an app from your browser's menu. That cache contains only the site's files, never anything you generated. When a new version is published (the build id in the footer changes), the cache is replaced on your next visit.
Honest limits
A random generator cannot protect a device that is already compromised: malware, a keylogger or a malicious browser extension can read anything on your screen, this page included. Generate sensitive passwords on a device you trust, and if you want to be extra careful, use a private window with extensions disabled. Likewise, this site cannot know what a website does with the password you give it; that is what unique passwords and a password manager are for.
Found a problem? Security contact details are published at /.well-known/security.txt.