Entropy extraction / demonstration

Turning a hiss
into a password.

Drop in a WAV recording of noise. This page walks the bytes through hashing and rejection sampling, and shows you the arithmetic at each step. Everything runs in your browser. The audio never leaves this tab.

Waveform / awaiting input
SRC

Provide the noise

A 16-bit PCM WAV file. Microphone hiss, rain, a detuned radio. Longer is better, but the honest limit is discussed at the bottom of this page.

No file handy?
LIM

The honest limit

Where this method stops working, and what to reach for instead.

Hashing spreads entropy, it does not create it. If your recording is ten seconds of near-silence carrying only a handful of unpredictable bits, SHA-512 gives you output that looks random while remaining exactly as guessable as that handful of bits. Every readout on this page would still show a clean bill of health. Shannon entropy measured on the hashed pool tells you the hash worked, never that the source was any good.
So use this page to understand the mechanism, not to secure anything. For passwords you actually intend to rely on, call crypto.getRandomValues(). It draws from the operating system's entropy pool, which is continuously reseeded from hardware sources that were designed for the job. That is the button above marked Synthesise noise, and it is the only source on this page whose unpredictability is worth trusting.