- Does SecurePass send or store my passwords?
- No. Passwords are generated and analysed by code running in your browser, and they are never sent, saved or logged. The page's security policy only allows network requests to SecurePass itself and, if you press the button, the breach-check service. Even then only five characters of a hash leave your device.
- How can I check that for myself?
- Open your browser's developer tools, choose the Network tab, and use the generator and strength checker. No requests appear. You can also turn on airplane mode after your first visit: SecurePass keeps working because it runs entirely on your device. The network counter on this page shows the same thing live.
- Does it work offline?
- Yes. After your first visit a service worker keeps a copy of every page, script and wordlist on your device, so SecurePass loads and works without a connection. Only the optional breach check needs the internet.
- Is the breach check private?
- Yes. It uses k-anonymity: your device hashes the password with SHA-1 and sends only the first five of its forty characters to Have I Been Pwned. The reply lists every breached hash that starts with those characters, padded with decoys, and your device looks for a match itself. See how it works.
- What can't SecurePass protect against?
- Anything that already has access to your device or screen. A malicious browser extension can read any page you open. Malware can read your keyboard and clipboard. Clipboard history and sync features, such as Windows clipboard history or Apple's Universal Clipboard, may keep or share a copy of anything you copy. And someone looking over your shoulder can read your screen, which is why you can hide the generated password.
- Why does the checker rate a long password as weak?
- Length only helps if the characters are unpredictable. The strength checker looks for the patterns that cracking tools try first: common passwords, dictionary words, names, dates, keyboard runs like qwerty, repeats and predictable substitutions like @ for a. A long password built from those patterns can fall in seconds.
- Should I use a password or a passphrase?
- Both are strong when they are random and long enough. A random password packs more strength into fewer characters, which suits a password manager. A passphrase of six or more random words is far easier to type and remember, which suits the few passwords you type by hand, like your password manager's own.
- How random is it?
- Every character and word comes from
crypto.getRandomValues, your browser's cryptographically secure random number generator, the same source browsers use for encryption keys. SecurePass discards any random number that would make some characters more likely than others, so every possible password is equally likely.
- Is it really free?
- Yes, with no ads, accounts or tracking. SecurePass is a set of static files, which cost nothing to serve, and the source code is open under the MIT license.