Mapping eight numbers to three characters changes the counts

Assume integers from 0 through 7 are equally likely, and use the remainder after division by 3 as a character index. Remainders 0 and 1 each appear three times; remainder 2 appears twice. Even when the original numbers are uniform, the remainders are not. This is modulo bias in this example.

0 % 3 = 0    1 % 3 = 1    2 % 3 = 2
3 % 3 = 0    4 % 3 = 1    5 % 3 = 2
6 % 3 = 0    7 % 3 = 1
// counts: [3, 3, 2]

Rejecting the last two numbers gives equal counts

In this small example, reject 6 and 7 and draw again. The accepted numbers 0 through 5 produce each remainder twice. Assuming uniform original numbers, this removes the bias within the accepted range. Drawing again means requesting a new number, not reusing the rejected number.

Remainder counts 3, 3, 2 for numbers 0 through 7 divided by 3, compared with counts 2, 2, 2 after rejecting 6 and 7.
An original count diagram calculated from the small example. The left panel includes all numbers from 0 through 7; the right accepts only 0 through 5. This is not a measured distribution of browser randomness.

Moyoutil’s randomInt function fills Uint32Array(1) using crypto.getRandomValues. It sets a boundary by dividing 2^32 by the number of choices, rounding down and multiplying by that number of choices. Values at or above the boundary are rejected and drawn again. For three choices, the boundary is 4,294,967,295, so only the maximum value is rejected.

Math.floor(4294967296 / 3) * 3
// 4294967295
// accept: 0 through 4294967294
// reject: 4294967295

W3C Web Cryptography: getRandomValues

The Web Cryptography specification requires getRandomValues to generate cryptographically strong random values. Our checks verify the project’s handling of the rejection boundary; they do not audit operating-system entropy or a particular browser’s random-number implementation.

Including character types differs from independently selecting every position

The tool first selects one character from each chosen type, fills the remaining positions from the combined set, then shuffles the order. Each chosen type therefore appears at least once. Selecting only uppercase letters and selecting all four types are different generation conditions. Including character types alone does not guarantee password security, and a simple count of combinations cannot establish an actual guessing time.

Length must be an integer from 4 through 128, with at least one character type selected. Fractional lengths, out-of-range lengths and deselecting every type produce errors. Accepting four characters does not mean four is a safe minimum length. For verifiers within its scope, NIST SP 800-63B-4 requires at least 15 characters for passwords used as single-factor authentication, and at least eight for passwords used as part of multifactor authentication. These are not universal input rules for every website.

NIST SP 800-63B-4: Password verifier requirements

Distinguish storing a result from clearing the screen

  1. Check the service’s allowed length and characters. Moyoutil defaults to a length of 20; you can adjust the length and character types.
  2. Select Generate new password to create a result for the current settings. Changing a setting clears the old result and disables copying, so generate again.
  3. Use a different password for each service and store it in a password manager. This tool is not a password vault and does not sign in to services.
  4. Clear screen result empties the displayed result but does not delete text already copied to the clipboard. Check the clipboard and shared-device state separately.

NIST SP 800-63B-4: Password managers and distinct passwords

Generated results are not sent to or stored on the tool’s server. This does not block extensions that read input or the clipboard, shared-device risks, or account phishing. Do not use published example strings as real account passwords.

Frequently Asked Questions

Do I need every special character type for security?

Character types alone cannot determine security. Check the service’s requirements, sufficient length, distinct values for different services and safe storage together.

Does this article validate browser randomness?

No. We enumerated a small range and reproduced the project function’s rejection boundary. We did not measure a browser’s entropy or password-cracking time.