2026-08-28 · ShishwaLab Editorial
Password Strength: What Checkers Measure (and What They Don’t)
A practical explanation of password strength signals, entropy intuition, and private generation with ShishwaLab.
About the author: Writers and engineers at Shishwa Technologies who build and document ShishwaLab’s free utilities.
Strength is about guessing difficulty
A strength meter is not a crystal ball. It estimates how hard a password would be to guess or brute-force under common attack models. Longer passwords with more character variety generally score higher because the search space grows quickly. Reused passwords, dictionary words, and keyboard walks score poorly because attackers try those first.
ShishwaLab’s password generator creates random strings in your browser with Web Crypto and shows simple strength feedback so you can tune length and character sets before you copy the result into a password manager.
Signals most checkers look at
- Length: often the strongest practical lever for random passwords.
- Character set: upper, lower, digits, and symbols increase combinations.
- Obvious patterns: sequences like “123456”, “qwerty”, or repeated blocks.
- Dictionary-like structure: words and years that appear in breach lists.
- Repetition and low variety: “aaaaaaA1!” is long but still weak.
What meters cannot know
A meter cannot know whether your password appeared in a breach unless it checks an online database. It cannot know if you reused the password on five other sites. It cannot see whether malware will keylog the next login. High score ≠ safe account if reuse or phishing is in play.
That is why the best “strength” upgrade is process: unique password per site, stored in a manager, with MFA where available. The generator’s job is to make uniqueness easy without uploading candidates to a server.
How to generate a password privately
Open the Password Generator, choose length (12–16+ for many accounts; longer for important vault keys), enable the character classes your site allows, generate, then copy once into your manager. Avoid pasting passwords into chat tools or email drafts “for later.”
If a website forbids symbols, increase length instead of inventing a clever phrase you will reuse. If you must memorize a passphrase, use multiple unrelated words with length on your side—and still prefer a manager for site logins.
Worked intuition
A purely random 8-character lowercase password has 26^8 possibilities—large for a human, small for modern guessing hardware when unsalted or offline attacks apply. Move to 16 characters across mixed classes and the space becomes vastly larger. Clever substitutions (“P@ssw0rd”) add less than people think because those patterns are in attacker dictionaries too.
Practical checklist
- Unique password per important account.
- Prefer length over cleverness for random secrets.
- Store secrets in a password manager, not a notes app screenshot.
- Enable MFA for email, banking, and cloud consoles.
- Generate secrets in a client-side tool when you do not want upload risk.
Bottom line
Strength checkers measure structure and estimated guess resistance. They do not replace unique passwords, MFA, or good device hygiene. Use them as coaching while you generate and store better secrets.
Related tool
Password Generator & Strength Checker
Generate secure random passwords and test password strength with simple feedback.
Open Password Generator & Strength Checker