Password Generator Guide
A strong password is one you can store and an attacker cannot guess. Clever substitutions are not a scheme.
rookvpn.com/pass draws passwords in the browser. The string is not saved on the server. If you close the tab without putting it in a password manager, it is gone, which is what you want for a secret and a problem if it was the only copy.
Random passwords
Use the generator when a machine will store the password. Set the length to what the site actually keeps. A site that silently truncates to 16 characters has stored a different password than the one you think you created. Turn off ambiguous characters only when a person must read the password aloud. That option is for transcription, not for extra strength.
Generate a different password for each site. Five passwords on one screen are five passwords, not one password you reuse because they were visible together.
Passphrases
Use a passphrase when a human must type it often. Keep the words the page drew. Replacing a word with a birthday or a pet name removes the randomness you just paid for. Four words is a floor. A master passphrase should be longer. A sentence you invented is not this tool.
Sites that reject spaces need the symbol password, not a passphrase with the spaces deleted.
Breach check
The Have I Been Pwned check sends a hash prefix, not the password. A hit means that password is in a published corpus. Retire it everywhere it was reused, then generate a replacement. A miss does not mean the password is long enough. It means this dataset did not contain it.
Handing it to someone else
Do not email the password next to the username. Put the password in a one-view link on rookvpn.com/secret and send the username in the normal channel. If you also need a bcrypt hash for an application test, use rookvpn.com/hash/bcrypt at the application’s cost, and do not paste the raw password into the ticket beside the hash.