Guides
Password entropy explained
Entropy is a way to count how many guesses an attacker would need.
Entropy in bits is log base 2 of the number of equally likely possibilities. Each added bit doubles the work for an attacker. A random password with 80 or more bits is out of reach for guessing with current hardware, as long as it is stored properly.
The formula
For a password made of random characters: bits = length x log2(pool size). With 26 lowercase letters, each character adds about 4.7 bits. With all 94 printable ASCII characters, about 6.55 bits. A word list of 7,776 words adds about 12.9 bits per word.
What the meter shows
- Bits: computed from the size of the pool and the length, using the settings you chose.
- Level: a label for the bit count (Weak below 40, Fair below 60, Strong below 80, Very strong below 100, Excellent from 100).
- Estimated time: the average time to find the secret at ten billion guesses per second, which is on the fast side for an offline attack on a quick hash. Slow, well-designed password hashing makes real attacks far slower.
Limits of the estimate
- Entropy only describes passwords picked at random. A password you invented has far less than its length suggests.
- The estimate assumes an attacker knows your settings but not the result.
- It does not measure how a service stores or protects passwords, which matters as much.
To generate a password and see its numbers, use the generator.
Frequently asked questions
How many bits do I need?
There is no single number. For online accounts, where attempts are limited, much less is needed than for an encrypted file that can be attacked offline. Around 80 bits or more is a comfortable target for important secrets.