Text & everyday tools · Password Generator
Should you trust an online password generator? What to check first
· Why it matters
passwords privacy trust
Gives a checklist for judging a web-based password generator — where the randomness comes from, whether anything is sent, what scripts load, whether limits are documented — and explains why 'free' generators differ so much.
A password from a stranger — the odd idea of asking a website to invent your secret
Asking a website to invent a secret feels backward because a web page normally arrives through a network and executes code from someone else. The right response is neither blind trust nor a blanket claim that every online generator is unsafe. Inspect where random choices occur, what leaves the page, what scripts load and what state remains after use.
ToolAcre supports a scoped audit because the source and tests name those seams. That does not make its output safe for a compromised browser or every account. The checklist establishes product behavior, while device trust, destination policy and later storage remain separate decisions.
Check the randomness source — cryptographic generator or general-purpose, and whether the page says which
Start with the random source. ToolAcre requires `crypto.getRandomValues`, probes it before enabling controls and throws if the engine cannot obtain it. All bounded choices pass through rejection sampling. A test scans production source to keep `Math.random` out, so the claim is enforced instead of being a marketing sentence.
Then inspect the reduction and shuffle rather than stopping at the API name. Cryptographic bytes can still be reduced badly. Here, uneven tails are rejected before modulo and character positions are shuffled with secure bounded integers. If another tool does not describe or expose this path, uncertainty remains even if it mentions Web Crypto.
Check the network — does generating a password trigger any request, and does the page load third-party scripts, ads or analytics
Watch the network while the page loads, generates and copies. ToolAcre legitimately downloads static wordlists from its own origin. Browser tests distinguish those public assets from credential traffic and assert that Generate and Copy add no requests. The product registry disables analytics and advertising on every password page.
A nonempty network panel is therefore not automatically a failure. Check request purpose, destination, method and body, and search for the assembled value. Also inspect the CSP, which restricts this product’s connections to its own origin. Network silence is one layer, not proof against local extensions or malware.
Check the wordlist — a published list such as the EFF's versus an unknown home-made one
The shipped vocabulary is not an unnamed home-made pool. Three committed EFF files are listed in options, credited in product content and checked at build time against advertised nonblank line counts: 7,776 for the long list and 1,296 for each short list. Selection uses the actual loaded and filtered words.
A public list is compatible with secure generation because list secrecy is not an assumption. The random index is the unknown choice. Still, filtering by word length changes the eligible count, so a careful tool should calculate from the resulting pool rather than keep quoting the full file size.
Check the documentation — does the tool state what it will not do and where its limits are
Documentation should state both behavior and limits. ToolAcre names word and character bounds, English-only assets, one-value-at-a-time generation, no reproducible seed, no breach checking and the requirement for a working cryptographic browser source. It also states that entropy figures describe settings under assumptions rather than guaranteeing a result.
Failure paths are part of that honesty. Empty or missing lists, impossible acrostics, invalid ranges, absent character groups, excessive or insufficient lengths, clipboard refusal and missing Web Crypto receive explicit responses. A generator that only documents its happy path leaves the most consequential behavior unreviewed.
Check what stays behind — history, autosave, clipboard, and whether a Clear data control exists
The workbook claims a Clear data control, but the interface has none. The corrected behavior is more specific: Generate replaces the one current state value, changing meaningful settings clears it, and navigating away discards it because no storage or history exists. The output remains a text node in the DOM until one of those actions occurs.
Copy happens only after the user presses Copy and uses `navigator.clipboard.writeText`. The code does not clear the clipboard automatically, inspect clipboard history or control an operating-system clipboard manager. If permission is refused, it displays an error and asks the user to select and copy manually.
Check what remains: one current DOM value, an explicit clipboard write, and no Clear data control
Browser extensions and password-manager generators execute with different privileges and storage models, so this checklist cannot audit them by proxy. A manager may be exactly the right place to generate and store site credentials, but that is a separate product decision. ToolAcre provides no vault or autofill.
Likewise, an online generator should not be used on a shared or untrusted device merely because network checks pass. Software with local access can read the output or clipboard. Trust assessment must include the endpoint, not only the website origin.
The takeaway — the Password Generator passes each check openly, and you should expect the same from any tool you use
ToolAcre passes a transparent set of checks: mandatory Web Crypto, rejection sampling, verified static lists, same-origin loading, no generation request, no analytics or ads, no persistent storage, no history and an explicit clipboard action. Each claim has a source or test path a reviewer can inspect.
The conclusion remains conditional. Use the evidence to decide whether this generator fits a particular situation, then keep each generated value private and unique. Do not treat a checklist pass as permission to reuse, transmit or store credentials carelessly, and do not confuse generation with management.