Salta al contenuto

Generatore Crittografico di Password Sicure

Genera password ad alta entropia nel browser con window.crypto.getRandomValues. 100% locale, nessuna telemetria né trasmissione di rete.

Configura le opzioni e fai clic su Genera

Generatore Crittografico di Password Sicure

100% CSPRNG Locale

Genera password ad alta entropia nel browser con window.crypto.getRandomValues. 100% locale, nessuna telemetria né trasmissione di rete.

Set di Caratteri

20 caratteri
82064128
Set di Caratteri

Robustezza Password

Robustezza Password:Molto Forte
Dimensione del Pool: 89Entropia di Shannon Stimata: ~129.5 bit

L'entropia è una stima matematica teorica basata sulla dimensione del pool e sulla lunghezza, non una garanzia assoluta contro attacchi mirati.

Password Generate

Configura le opzioni e fai clic su Genera

Le password generate non vengono mai inviate sulla rete, mai registrate e mai salvate nella memoria locale o di sessione.

Cryptographically Secure Randomness vs. Pseudo-Random Number Generators

Standard JavaScript Math.random() relies on pseudo-random number algorithms (such as xorshift128+) designed for speed rather than cryptographic unpredictability. Because PRNG internal state can be reconstructed from observed sequence outputs, passwords generated via Math.random() are fundamentally vulnerable to reverse-engineering and statistical prediction attacks.

This tool utilizes window.crypto.getRandomValues(), which interfaces directly with the host operating system's cryptographic random number generator (such as /dev/urandom on Linux and macOS or CryptGenRandom / BCryptGenRandom on Windows). This guarantees true cryptographically secure pseudo-randomness (CSPRNG) with maximum information entropy.

Information Entropy Calculation (Shannon Entropy)

Password strength is mathematically measured in bits of entropy using Shannon's entropy formula:

Entropy (bits) = L * log2(R)
  • L = Password length in characters
  • R = Size of the available character pool (e.g. 90 unique characters when uppercase, lowercase, numbers, and symbols are enabled)

A 20-character password drawn from a pool of 90 characters delivers approximately 130 bits of entropy, requiring an astronomical 2130 brute-force attempts to exhaust the keyspace—far exceeding modern supercomputing capabilities.

Guaranteed Character Representation and Unbiased Shuffling

Many simplistic password generators pick random characters from a concatenated pool, which creates a probabilistic risk that a required character class (such as special symbols or digits) might be omitted in a specific password.

Our generator enforces strict representation: at least one character is selected directly from each active class, remaining positions are populated uniformly from the combined pool using rejection sampling to eliminate modulo bias, and the entire character array undergoes an unbiased cryptographic Fisher-Yates shuffle.

Zero-Retention & Zero-Backend Privacy Architecture

In accordance with strict zero-knowledge security standards:

  • 100% Client-Side: All computations execute strictly within your local browser JavaScript engine. No passwords, seeds, or parameters are ever sent to an external server.
  • Zero Persistence: Generated passwords exist solely in ephemeral memory and are never written to localStorage, sessionStorage, cookies, or indexed databases.
  • Zero Auto-Copy: Passwords are never placed into your system clipboard without an explicit user click on the Copy action button, preventing clipboard snooping attacks.

Frequently Asked Questions

Le password generate vengono inviate a un server?
No. La generazione avviene interamente nella memoria del browser tramite window.crypto.getRandomValues, senza alcuna chiamata di rete.
Perché usare crypto.getRandomValues anziché Math.random?
Math.random genera valori pseudocasuali prevedibili. crypto.getRandomValues si interfaccia con il kernel crittografico del sistema operativo.
Le password vengono memorizzate nella cronologia o nel localStorage?
Assolutamente no. Le password risiedono unicamente nella memoria effimera di React. Nel localStorage vengono salvate solo le preferenze non sensibili.