The commonly used Math.random() is actually a pseudorandom number generator — it follows a deterministic algorithm and is theoretically predictable. For something like passwords, that's not good enough.
This tool uses the Web Crypto API's crypto.getRandomValues() instead. It draws from OS-level entropy (hardware noise), producing truly unpredictable values that are safe for cryptographic use.
The generation logic itself is straightforward: take the selected character types (uppercase, lowercase, numbers, symbols) and concatenate them into one long "charset" string. Then, for each character position, pick a random number and use n % charset.length as an index into that string. Repeat for the desired password length.
Your preferences for length and character types are saved in localStorage, so the same settings are restored next time you visit.