Tech & everyday
Password strength calculator
Strength is measured in bits of entropy, which is just a way of counting how many guesses an attacker would need. Length raises it far faster than adding symbols does.
Do not type a real password anywhere, including here. This tool works from length and character set alone, so describe your password rather than entering it.
Entropy maths only holds for genuinely random choices. Human-chosen passwords are far weaker than their length suggests.
Entropy is just counting guesses
Password strength is measured in bits of entropy. Each bit doubles the number of guesses required, so 40 bits means roughly a trillion possibilities and 60 bits means about a quintillion.
Every character drawn from a 95-symbol keyboard set contributes about 6.6 bits. Every character from lower-case letters alone contributes 4.7. This is the entire mathematics of the subject, and it leads somewhere counterintuitive.
Length beats complexity, decisively
| Password shape | Entropy | Verdict |
|---|---|---|
| 8 characters, full symbol set | 52 bits | Falls to an offline attack |
| 12 characters, lower case only | 56 bits | Stronger, and easier to type |
| 16 characters, full symbol set | 105 bits | Not brute-forceable |
| Four random common words | ~52 bits | Memorable, moderate |
| Six random common words | ~78 bits | Memorable and strong |
Adding one character to a lower-case password multiplies the search space by 26. Adding symbols to an eight-character password multiplies it by roughly 4.5 in total. Length is the lever, which is why NIST’s current digital identity guidelines (SP 800-63B) dropped mandatory composition rules and forced periodic rotation, and recommend supporting long passphrases instead.
Why the maths overstates real passwords
The entropy formula assumes every character is chosen uniformly at random. Human-chosen passwords are nothing like uniform. They start with a capital, end with a digit or exclamation mark, are built on dictionary words, and substitute 3 for e and @ for a — patterns that cracking tools apply first, not last.
Analyses of breached password sets repeatedly find that a substantial share of real passwords fall to a well-built dictionary attack in minutes, regardless of how many character classes they technically contain. “P@ssw0rd123!” satisfies every composition rule ever written and is worthless.
What actually protects an account
- A password manager generating long random strings you never see, let alone remember. This solves length, uniqueness and reuse simultaneously.
- Uniqueness above all — a strong password reused across sites is only as safe as the weakest site holding it. Credential stuffing is a bigger practical threat than brute force by a wide margin.
- Multi-factor authentication, which defeats a stolen password entirely. Hardware keys and passkeys resist phishing in a way that SMS codes do not.
- Passphrases of several genuinely random words, where memorisation is unavoidable.
One caveat about crack times generally: they assume brute force, and brute force is rarely how accounts are lost. Phishing, credential reuse from an unrelated breach, malware on the device and password reset flows through a compromised mailbox all bypass password strength completely.
A note on this tool
This calculator deliberately takes a length and a character set rather than a password. There is no reason to type a real password into any website, including this one, and a tool that asks you to is training a habit worth not having. The arithmetic is identical either way.
Common questions
How long should a password be?
At least 16 random characters where a manager generates it, or five to six random words for a passphrase you have to remember. Twelve random characters from a full keyboard set is around 79 bits and still respectable; eight characters is not adequate for anything you care about, whatever symbols it contains.
Are passphrases really as strong as random passwords?
They can be, if the words are chosen randomly rather than by you. Four words drawn at random from a 7776-word list gives about 52 bits; six words gives about 78. The catch is that words you pick yourself, or a phrase from a song or book, carry a small fraction of that — the randomness has to come from a real random source.
Should I change my passwords regularly?
Not on a schedule, according to current NIST guidance. Forced rotation pushes people toward predictable increments like Spring2024 becoming Summer2024, which is weaker than leaving a strong password alone. Change a password immediately if there is any sign of compromise, and prioritise unique passwords per site over frequent changes.
Is this checker safe to use?
It never asks for your password, which is the point. It calculates from the length and character set you describe, entirely in your browser, and nothing is transmitted anywhere. As a general habit, treat any site that asks you to paste a real password for "checking" as untrustworthy.