← All articles

Is It Safe to Generate Passwords and Random Numbers Online?

2026-09-13 · 6 min read · Security Concepts

If you have ever generated a password or a random number on a website and wondered "is this actually random, or could someone guess it?", you were asking the right question — and the answer depends entirely on where the randomness comes from. This article explains the difference in plain language and tells you what to look for.

Two kinds of random, with very different trust levels

Most "random number generators" in programming are pseudo-random: they run a fixed mathematical formula, and if you know the formula and the starting seed, you can predict every number they will ever produce. That is fine for shuffling a playlist or deciding who goes first in a game, and it is fast. But it is absolutely not fine for anything where predictability is a security problem.

The other kind is cryptographically secure randomness, which draws from unpredictable physical or system-level sources — mouse movements, keyboard timing, hardware noise — so that even the software itself cannot predict the next value. This is what passwords, tokens, and encryption keys must use.

Why a predictable password generator is dangerous

Imagine a password generator that uses the simple kind of random. An attacker who learns the formula and the seed — and seeds are often something guessable like the current time — can reproduce every password the generator has ever produced. A password that is "random" but predictable is no better than writing the password down in public.

The practical upshot: the only random generator you should trust for passwords is one that uses your browser's cryptographically secure source. Browsers expose this as the Web Crypto API, and any tool that uses it is drawing from the same unpredictability that secures HTTPS connections.

Does "runs in the browser" make it safer or less safe?

For random numbers and passwords, client-side is actually the safer option, for a simple reason: your freshly generated password never travels over the network to a server that might log it. A server-side password generator has to receive your request, generate a value, and send it back — which means the password existed on someone else's machine, however briefly.

A client-side generator produces the password on your own device, using the Web Crypto API, and it goes straight to your clipboard or screen. There is no server in the loop that could leak, log, or be compelled to hand over the value.

What to check before you trust a generator

Three quick checks separate the trustworthy tools from the rest:

  1. Does it say it uses crypto-secure randomness (Web Crypto API, or "cryptographically secure")? If it does not say, assume it is the predictable kind.
  2. Does it let you control the length and character set? A good generator lets you demand length (16+ characters) and mix of upper/lower/digits/symbols.
  3. Is it client-side? You can confirm with the DevTools network check described elsewhere on this site — generate a password and watch for zero network requests.

The same logic applies to "fair" draws

This is not just about passwords. The same distinction governs coin flips, dice rolls, and raffle draws. A "random" name picker built on a predictable formula can be gamed, which is why a fair giveaway needs the cryptographically secure source too. When the stakes are a contest or a decision that matters, "random enough for a game" and "actually unpredictable" are two different bars, and you want the second one.