hasibai

Tech & everyday

Password strength calculator

Strength is measured in bits of entropy, which is just a way of counting how many guesses an attacker would need. Length raises it far faster than adding symbols does.

Do not type a real password anywhere, including here. This tool works from length and character set alone, so describe your password rather than entering it.

Entropy maths only holds for genuinely random choices. Human-chosen passwords are far weaker than their length suggests.

Strength estimate
Choose a length and character set.

Entropy is just counting guesses

Password strength is measured in bits of entropy. Each bit doubles the number of guesses required, so 40 bits means roughly a trillion possibilities and 60 bits means about a quintillion.

bits = length × log₂(size of character set)

Every character drawn from a 95-symbol keyboard set contributes about 6.6 bits. Every character from lower-case letters alone contributes 4.7. This is the entire mathematics of the subject, and it leads somewhere counterintuitive.

Length beats complexity, decisively

Password shapeEntropyVerdict
8 characters, full symbol set52 bitsFalls to an offline attack
12 characters, lower case only56 bitsStronger, and easier to type
16 characters, full symbol set105 bitsNot brute-forceable
Four random common words~52 bitsMemorable, moderate
Six random common words~78 bitsMemorable and strong

Adding one character to a lower-case password multiplies the search space by 26. Adding symbols to an eight-character password multiplies it by roughly 4.5 in total. Length is the lever, which is why NIST’s current digital identity guidelines (SP 800-63B) dropped mandatory composition rules and forced periodic rotation, and recommend supporting long passphrases instead.

Why the maths overstates real passwords

The entropy formula assumes every character is chosen uniformly at random. Human-chosen passwords are nothing like uniform. They start with a capital, end with a digit or exclamation mark, are built on dictionary words, and substitute 3 for e and @ for a — patterns that cracking tools apply first, not last.

Analyses of breached password sets repeatedly find that a substantial share of real passwords fall to a well-built dictionary attack in minutes, regardless of how many character classes they technically contain. “P@ssw0rd123!” satisfies every composition rule ever written and is worthless.

What actually protects an account

One caveat about crack times generally: they assume brute force, and brute force is rarely how accounts are lost. Phishing, credential reuse from an unrelated breach, malware on the device and password reset flows through a compromised mailbox all bypass password strength completely.

A note on this tool

This calculator deliberately takes a length and a character set rather than a password. There is no reason to type a real password into any website, including this one, and a tool that asks you to is training a habit worth not having. The arithmetic is identical either way.

Common questions

How long should a password be?

At least 16 random characters where a manager generates it, or five to six random words for a passphrase you have to remember. Twelve random characters from a full keyboard set is around 79 bits and still respectable; eight characters is not adequate for anything you care about, whatever symbols it contains.

Are passphrases really as strong as random passwords?

They can be, if the words are chosen randomly rather than by you. Four words drawn at random from a 7776-word list gives about 52 bits; six words gives about 78. The catch is that words you pick yourself, or a phrase from a song or book, carry a small fraction of that — the randomness has to come from a real random source.

Should I change my passwords regularly?

Not on a schedule, according to current NIST guidance. Forced rotation pushes people toward predictable increments like Spring2024 becoming Summer2024, which is weaker than leaving a strong password alone. Change a password immediately if there is any sign of compromise, and prioritise unique passwords per site over frequent changes.

Is this checker safe to use?

It never asks for your password, which is the point. It calculates from the length and character set you describe, entirely in your browser, and nothing is transmitted anywhere. As a general habit, treat any site that asks you to paste a real password for "checking" as untrustworthy.