How the browser chooses characters
MorphPass uses crypto.getRandomValues, the browser’s cryptographic random source. It fails if secure randomness is unavailable; it does not fall back to Math.random. This is an explanation of the implementation, not certification of your browser or device.
Equal chances, without rounding bias
A random byte has 256 possible values. Ten number choices do not divide 256 evenly: reducing every byte modulo 10 would favor six numbers. For ten choices, MorphPass accepts 0–249, giving 25 byte values to each number, and rejects 250–255 before drawing again. Other choice counts use the same rejection principle.
Two ways to meet the rules
Simple mode builds a whole candidate. With every selected group required, it discards candidates missing a group and tries again. Exact mode draws the requested number from each filtered group, then shuffles with Fisher–Yates: each position swaps with an unbiased random choice among the remaining positions.
Exact quotas narrow the possible combinations compared with unrestricted choices from the full alphabet. Including four groups cannot rescue a very short password. There is no strength score or collision guarantee. Very restrictive simple-mode settings can reach the retry limit; the tool asks you to increase length or relax the group requirement.
The local checks cover rejection sampling, exact quotas, exclusions, small shuffle permutations and failure when randomness is unavailable. They are bounded implementation checks, not an independent security audit. See browser randomness documentation.
RESEARCHED OCTOBER 4, 2026
How passwords get compromised, and what you can do
Did you know? In Verizon’s 2026 Data Breach Investigations Report, credential abuse was the first identifiable way in for 13% of the non-Error, non-Misuse breaches it analyzed. But Verizon adds: “if you consider all instances of credential abuse at any point in the breach progression, it still sits on top at 39%.” The figure behind that statement covers 19,905 breaches. The report’s analysis window was Nov 1, 2024, to Oct 31, 2025. These are organizational breaches worldwide, not a count of individual US victims. Verizon 2026 DBIR, page 16; analysis window, page 9.
A password can be exposed without someone guessing every character. Here are five common routes and practical responses. They are not a ranked list, and more than one can be involved in the same account takeover.
Reusing a password
Attackers try username/password pairs leaked from one service against others. This is credential stuffing: even a long, random password loses its advantage if you reuse it after a leak. Give each account a different password and keep them in a password manager. That limits how far one exposed credential can travel. Verizon’s credential-stuffing research.
Choosing predictable patterns
Familiar words, personal details and small variations are easier to anticipate than independent random choices. Aim for 16 characters or more where the service allows it; MorphPass starts at 20. Adding a symbol is not a magic fix. Use length and randomness, and change a compromised password rather than relying on calendar-based rotation. CISA’s password guidance; NIST password guidance.
Entering it on a phishing page
A convincing message can lead to a fake sign-in page that collects a perfectly good password. Don’t use a login link in an unexpected message. Open the service yourself through a bookmark, its app or an address you type. When supported, passkeys provide phishing-resistant sign-in. A random password generator cannot tell whether a page asking for your password is genuine. NIST phishing guidance; FIDO passkeys.
Malware stealing credentials or sessions
Infostealer malware can take “financial credentials, cryptocurrency wallets, browser extensions, and multifactor authentication (MFA) details” from an infected computer, according to the FBI and CISA. Stolen session cookies may also let an attacker access an already authenticated session without repeating the normal password or MFA check. Keep software updated, avoid unexpected downloads, and never paste commands into a terminal or Run window just because a “CAPTCHA” tells you to. FBI/CISA infostealer advisory; FBI session-cookie warning.
A service’s password database being breached
Stolen password hashes can be attacked offline; the service’s storage protections matter alongside your password choice. Change affected passwords and any reused copies. Review recovery details and active sessions, and remove malware from a suspected compromised device before trusting new credentials to it. Use the service’s recovery process if you have lost access. NIST on offline attacks; FTC recovery steps.
What MorphPass helps with
MorphPass uses browser cryptographic randomness and offers exact counts and exclusions for a service’s format rules. It does not save a password history. It cannot prevent phishing, remove malware or fix a breached service. Enable MFA or use passkeys where available, alongside unique passwords and device care; none of these measures stops every attack.
If you suspect an account takeover, start with the provider’s recovery instructions. Secure the email account used for resets and check unfamiliar recovery information or signed-in devices before moving on to other accounts. FTC account recovery guidance.
Questions about the actual tool
Can exact counts work with a custom alphabet?
No. Exact group counts are available in Password and Alphanumeric presets. Custom mode samples from your deduplicated, filtered alphabet without group quotas.
Can characters or entire results repeat?
Yes. Repeated characters and duplicate results are allowed. A batch is not guaranteed to contain unique strings, and MorphPass cannot check whether a code was used elsewhere.
Does skipping look-alikes remove every confusing pair?
No. It currently removes I, lowercase l, 1, O, 0, lowercase o and |. Fonts can make other characters look similar. Add your own exclusions for a particular format.
Do exclusions change the length?
No. They remove choices before sampling. An exact quota stays the same, so a positive quota needs at least one character left in that group. Selection then applies to the remaining choices.
Can this issue recovery codes or API keys?
It creates random strings. Recovery codes and API keys normally must be issued and registered by the service that validates them. MorphPass cannot register a value, make it a valid key or grant access permissions.
Where will the advertising go?
The plan is Google AdSense ads on this information site’s guide pages only, after Google approves the site. The separate generator stays free, with no ads, analytics or other third-party scripts. No ad code is installed in this copy. The privacy page describes the advertising cookies and the consent banner for visitors in the EEA, UK and Switzerland. Approval and revenue are not guaranteed. Your settings stay inside the tool and are never passed in the Generate link.