Password length beats password complexity
The password generator defaults to a long random string rather than a short one with mandatory symbols. That ordering is intentional.
Against an offline attack the only thing that matters is search space. Tr0ub4dor&3 feels strong and is roughly 10^11 guesses. A 20-character lowercase passphrase is around 10^28 — and it is easier to type.
Complexity rules mostly exist to satisfy checkers, not attackers. They push people toward predictable substitutions (a → @, o → 0) which cracking tools try first.
Two things the generator does that matter more than symbol count:
- Uses the platform CSPRNG, never
Math.random. - Never sends anything anywhere — you can watch the network tab stay silent.
The strength meter is deliberately conservative. It reports entropy of the generated string, not how confident you should feel about the site you are about to use it on.