Password Strength Entropy Calculator
Measure how strong a password is using entropy in bits, E = L x log2(R), where L is the length and R is the size of the character pool. See the total number of combinations, the strength band from Very Weak to Very Strong, and an estimated crack time against attackers from throttled logins to a nation-state GPU cluster.
🎯Real Password Pattern Presets
🔑Password Composition
Total number of characters L in the password.
Guesses per second used for the crack-time estimate.
Pool R adds up: lowercase 26, uppercase 52, digits 62, symbols 95 total.
🔢Character Pool Snapshot
📋Bits Per Character by Pool
| Character Pool | Pool Size R | Bits per Char log2(R) | Example Set |
|---|---|---|---|
| Digits only | 10 | 3.32 bits | 0-9 PIN |
| Lowercase only | 26 | 4.70 bits | a-z |
| Lower + upper | 52 | 5.70 bits | a-z A-Z |
| Letters + digits | 62 | 5.95 bits | a-z A-Z 0-9 |
| Hex digits | 16 | 4.00 bits | 0-9 a-f |
| Full printable ASCII | 95 | 6.57 bits | alnum + symbols |
| Diceware word | 7776 | 12.9 bits | one word roll |
| Extended set | 128 | 7.00 bits | with more symbols |
📊Entropy Strength Bands
| Entropy Range | Band | Rough Meaning | Typical Example |
|---|---|---|---|
| Below 28 bits | Very Weak | Instant to crack | 6-digit PIN |
| 28 to 35 bits | Weak | Cracked quickly | 8 lowercase |
| 36 to 59 bits | Reasonable | Resists casual attack | 10-char alnum |
| 60 to 127 bits | Strong | Safe from most attackers | 12-char ASCII |
| 128 bits and up | Very Strong | Infeasible to brute force | 20-char random |
⏳Crack Time vs Length and Charset Grid
| Length | Lower 26 | Alnum 62 | ASCII 95 | Bits (ASCII) | Band (ASCII) |
|---|---|---|---|---|---|
| 6 chars | Instant | Seconds | 4 seconds | 39.4 | Reasonable |
| 8 chars | Instant | 4 hours | 7 hours | 52.6 | Reasonable |
| 10 chars | 2 hours | 3 years | 60 years | 65.7 | Strong |
| 12 chars | 2 months | 11k years | 530k years | 78.8 | Strong |
| 14 chars | 100 years | 42M years | 4.8B years | 92.0 | Strong |
| 16 chars | 68k years | 160B years | 44T years | 105.1 | Strong |
| 20 chars | 31B years | Astronomic | Astronomic | 131.4 | Very Strong |
| 24 chars | Astronomic | Astronomic | Astronomic | 157.7 | Very Strong |
🖥Attacker Guess Rates
| Attacker Scenario | Guesses per Second | Where It Applies | Threat Level |
|---|---|---|---|
| Online throttled | 1,000 (1e3) | Login with rate limits | Low |
| Online unthrottled | 1 million (1e6) | API with no lockout | Moderate |
| Offline bcrypt slow hash | 10,000 (1e4) | Leaked bcrypt database | Moderate |
| Offline MD5 GPU rig | 10 billion (1e10) | Leaked fast-hash dump | High |
| Nation-state cluster | 1 trillion (1e12) | Massive GPU or ASIC farm | Extreme |
⚙Formula Breakdown
💡Password Entropy Tips
Every time some site warns me that my password is weak because it doesn’t have a symbol in it, I’m pissed off, and I know why: Nobody ever explains why having more complex passwords would make them stronger. Changing an ‘a’ to a ‘!’ or putting a 3 instead of an ‘e’ must be making the password stronger, right? Nope.
Adding symbols helps widen the pool, but they matters less than length; entropy cares more about uncertainty. It cares about uncertainty. The password strength entropy calculator turns this vague question into a concrete answer that you can argue back against. And it’s expressed as number of bits. The formula calculates it as product of length times the log of size of your character pool.
Why Length Is Better Than Complexity
Password entropy is the measure of uncertainty about your password. For every bit added to a password, there are twice as many possibilities. If I had a 40-bit password, it could be any one out of a trillion equally probable choices. Entropy doesn’t measure the password’s length or characters; rather, it measures how well the process that produced this password did its job.
You might choose “password” as a password or generate a random twelve-letter string. Both has twelve characters, yet only the randomly generated one gets full marks on entropy scale. An actual attack will guess common words and sequences early on. This calculator assumes your characters is chosen separately from the set. It tells you the honest maximum of what would be secure.
For any slot in a password, there are however many choices available depending on size of your character pool. There are twenty-six lowercase characters. That’s fifty-two with uppercase thrown in. That’s sixty-two if you throw digits into the mix. Throw symbols in there too and now you’ve got ninety-five choices. The more sets you enable, the bigger the pool gets and the more bits each individual character have.
So complexity rules. But it is not as much as you would think. Yes, having some symbols helps. Usually adding length helps much more. That multiplies amount gained from each additional character by the number of characters. And that’s where most users go wrong: not using length as their main source of leverage.
These become real when we plug some numbers into formula. For example, with a pool of sixty-two characters, you get on average about six bits per character. If I pick a dozen out of that pool for my password, that’s about seventy-one bits of entropy. Now switch to the full ASCII pool, and now each character is worth around seven bits. That takes us up to about seventy-nine bits for that same password length. Bump it up another four characters like that and you’re over one hundred five bits.
The tool also displays this arithmetic to show how your length and charset interact. It helps keep you honest so you do not trust a colored bar that might be hiding the math. The size of the search space (the number of possibilities) is two raised to the power of entropy. So if you have an attack where you don’t need to test every possibility, then the thing to care about is the average number of guesses needed, i.e., half the keyspace. That’s why the calculator shows you both. Because sometimes seeing the raw scale makes it more convincing than having some sort of band label on it. It reminds you that security isn’t absolute but a game of statistics.
The speed at which an attacker is able to try your password determines crack time. Online, a web app may have a throttling limit of one thousand guesses per second. With a database leak and fast hashes, a GPU rig could send out billions of attempts per second. The same password that looks bulletproof online can be cracked in hours offline. It all depends off the context. This isn’t simply about picking a password. You’re selecting your resistance to a certain kind of attack for a given amount of time.
The tool plots those numbers onto a set of strength bands so you can read it easily. If it’s less than twenty eight bits, it’s very weak. It will fall immediately to almost any attacker that could realistically exist. Strong (safe from practically every possible attacker) is between sixty and one hundred twenty seven bits. Anything 128-bits or above makes brute force physically infeasible. The cut-offs match typical security advice. Aim for strong or better if it matters.
Entropy is a limit, but not a guarantee. Reusing a password across sites, or having it phished, does nothing to protect you from a hundred bit password. The time to crack numbers should be viewed as the strength of the lock. But then remember the door still needs unique passwords and two-factor authentication. Finally, using the calculator this way helps you think about security through real math instead of guessing. This applies whether it’s for you or your teams policy.

