PasswordXPrivate security instruments

How it works

Six short pieces: where the randomness comes from, what the numbers mean, and what they do not promise.

Cryptographic randomness

Every secret starts as bytes from your browser’s Web Crypto generator, the same primitive used for keys and sessions. Nothing here uses Math.random, and no value is derived from the time or from what you typed.

Why?

Picking a random character from those bytes needs care: reducing a byte with a remainder would make some characters more likely than others. PasswordX draws again instead, so every character of the set is equally likely.

How a secret is built

A password is drawn character by character from the set you choose. A passphrase draws whole words from the EFF list of 7,776. A PIN draws digits. A developer value draws raw bytes and encodes them.

Why?

Asking for at least one character of each selected type guarantees the shape you expect, and slightly narrows what can come out: the entropy shown is a bound, not the exact figure.

Entropy

Entropy counts how many possibilities an attacker must cover, on a log2 scale: one more bit doubles the work. Twenty characters from a set of 88 give about 129 bits; six random words give about 78.

Why?

That figure describes the way the secret was drawn, not the characters themselves. A password you invented does not get it, however unusual it looks.

Guessability

For a secret you already have, PasswordX asks a guess model (zxcvbn) how many attempts a real attacker would need, given dictionaries, names, keyboard patterns, dates and substitutions.

Why?

It is an estimate of habits, not a proof. It can be too kind to something it has never seen, and too harsh on something random that happens to contain a word.

Observations, not a score

Results are split in two: what the guess model concluded, and what our own rule checks recognized. Rules explain specific weaknesses in plain words; they are not exhaustive.

Why?

A single number out of 100 hides which part of a judgement is a measurement and which part is a guess. Separating them lets you see why a secret was rated the way it was.

Local processing

Generation and analysis happen in the page. The site is static, has no backend, and its Content-Security-Policy forbids network connections, so the page cannot send anything even by accident.

Why?

The limit is the device itself: an extension that can read the page, a clipboard that syncs, or a screen someone else can see are all outside what a web page can defend against.

The same explanations appear next to the controls they describe, inside each tool.