Why this uses crypto.getRandomValues
JavaScript's regular Math.random() isn't designed to be
unpredictable in a security sense — in some engines its internal state can
be inferred from enough output. Password generators should use a
cryptographically secure source instead, which is what the Web Crypto
API's getRandomValues() provides. That's what powers this tool.