Skip to main content
CalcMax

Password Strength Calculator

Range: 1 – 128

Result

95.3 bitStrong

Entropy

Character pool
62
Entropy per character
5.95 bit
Combinations (power of 10)
28

Password strength is arithmetic, and this page does the arithmetic instead of guessing. Pick a password length and a character set and you get the size of the pool those choices describe, the entropy in bits, and how long a modern graphics card needs to try every combination — under a fast hash and under a properly configured slow one. The gap between those last two numbers is the single most useful thing on the page: the same password that falls in three years against a leaked MD5 database survives millions of years against bcrypt. Length is the other half. Every extra character multiplies the work by the size of the pool, while adding a whole character set to a fixed length multiplies it once.

Crack time by entropy band

BandEntropyCombinationsSeconds at 10^10/sSeconds at 10^4/s
Weak28 – 35 bits8-24
Fair36 – 59 bits1006
Strong60 – 127 bits18814
Very strong128 bits and above382834

Read the last two columns as powers of ten: -2 means 10^-2 seconds, 3 means a thousand seconds. The right-hand column is the same attacker against a properly configured slow hash, so the two differ by a factor of a million. Entropy is the lower bound of the band, which is why this table and the strength badge always agree. Combinations are rounded down to a power of ten so they are never overstated.

Formula

entropy (bits) = password length × log₂(pool size), and the number of combinations is 2^entropy

password length
How many characters the password has
pool size
How many distinct characters are available: 26 lowercase, 26 uppercase, 10 digits, 32 symbols
log₂
Base-2 logarithm, so the result is counted in bits

Use it to compare two password policies before you write one, or to check whether a password you already have is worth keeping. It is exact for a password generated at random from a known character set, and only an upper bound for one a human invented — people pick patterns, so a 12-character password someone made up has far less entropy than 12 random characters. Brute force is also not the only attack: a password reused across sites is compromised by the other site's breach, and no amount of length helps there.

Worked examples

  1. 16 characters, letters and digits

    1. Pool: 26 + 26 + 10 = 62 characters
    2. Entropy per character: log₂(62) = 5.95 bits
    3. Total entropy: 16 × 5.95 = 95.3 bits
    4. Combinations: 10^28 — the tool reports the power of ten rather than all 29 digits

    95.3 bits clears the 60-bit band by a wide margin and lands in the top band normally reserved for 128. Turning on symbols as well would take the pool to 94 and the entropy to 104.6 bits — worth 9.3 bits, which is the same as adding about 1.6 characters.

  2. 8 characters, lowercase only

    1. Pool: 26 characters
    2. Entropy per character: log₂(26) = 4.70 bits
    3. Total entropy: 8 × 4.70 = 37.6 bits
    4. Combinations: 2^37.6 ≈ 2.1 × 10^11, so 10^11

    37.6 bits lands in the fair band — roughly seven seconds of work for a fast hash on one card. Doubling the length to 16 characters takes it to 75.2 bits, while leaving the length at 8 and switching every character set on only reaches 52.5 bits. Length does more per keystroke than variety does.

Limitations

The entropy figure assumes the password was generated uniformly at random from the character set you selected. Any password a person chose by hand has less, often far less, because people reach for words, dates and keyboard patterns that a cracking tool tries first. This page therefore measures the policy, not the password. The crack times are order-of-magnitude estimates from a single modern GPU, not a measurement of any particular machine: a determined attacker with a cluster, or simply a newer card, beats them by a large factor, and a stolen hash database can be attacked offline for as long as the attacker likes. Nothing here accounts for whether the password is reused, phished, keylogged or reset through a support desk — those are how passwords actually fall, and none of them are affected by entropy. Finally, the page will not generate a password for you, for the reason in the first paragraph of this file: a secure generator needs a cryptographic random source, which a pure calculation cannot be.

Frequently asked questions

How is password entropy calculated?
Entropy is the password length multiplied by the base-2 logarithm of the pool size. Choosing lowercase letters, uppercase letters and digits gives a pool of 62 characters, log₂(62) is 5.95 bits per character, and a 16-character password from that pool therefore carries 95.3 bits. The number of possible combinations is 2 raised to the entropy, which is why entropy is the useful unit: it adds up when the password gets longer.
Is 60 bits of entropy enough, and how do I read the crack time?
It depends entirely on how the site stores your password. At 10^10 guesses per second — one modern card against an unsalted fast hash — 60 bits is about three years of continuous work. Against bcrypt at cost 12 the same card manages around 10^4 guesses per second and the same password takes millions of years. So 60 bits is enough against a competent site and marginal against a careless one; 80 bits is enough against both.
Should I use symbols and mixed case, or just make it longer?
Longer is usually the better trade, and always the easier one to remember. Going from an 8-character lowercase password to 16 characters is worth 37.6 bits; keeping it at 8 characters but switching on every character set is worth 15 bits. The pool only multiplies once when you widen it, while every added character multiplies again. Use symbols when a site demands them, not because they are the efficient way to add strength.
Why will this page not generate a password for me?
A password is only as unpredictable as the source of randomness behind it, and a page that computes a displayed number cannot also draw from a cryptographically secure random source — that source is exactly what makes a generator different from a calculator. Use your password manager's generator or your operating system's, both of which do have one, and then use this page to check that the length and character sets you chose there are worth it.
Does a longer password always mean a stronger one?
Only if it was generated at random. Length is what the arithmetic rewards, and the arithmetic is why a four-word passphrase can beat a short jumble of symbols — but a 20-character password built from a song lyric, a birthday and a name is crackable with a dictionary, and its real strength is nothing like the 20 random characters this page measures. This page gives you the ceiling for a password policy; a password a person invented sits well below it.

References

Related calculators