This estimates the theoretical strength — in bits of entropy — of a randomly generated password with a given length and character set, and a rough offline brute-force time estimate against that full space.
How it works
Entropy
Entropy (bits) = length × log₂(character set size)
Character set size: lowercase adds 26, uppercase adds 26, digits add 10, symbols add roughly 32 — the total is however many of those classes are actually used.
What this can and cannot tell you
This measures the strength of a randomly generated password drawn uniformly from the stated character-set space — it does not, and cannot, know whether a specific password is actually easy to guess. “Password1!” uses all four character classes and would score respectably by this formula, while being one of the very first strings any real cracking tool tries, because dictionary words and common patterns are found by structure and known-password lists, not by exhaustive search through the entire character-set space this formula assumes. High entropy by this measure means “hard to guess by brute force if actually random” — it does not mean “safe,” if the password isn’t actually random.
The crack-time figure is a reference point, not a guarantee
It estimates offline brute-force time against the full character-set space, at a commonly cited guess rate — a rough order-of-magnitude figure, not a precise or universal one, since real attack speed varies enormously with the hash function protecting the password and the attacker’s hardware. A real attacker using a dictionary, known patterns, or a password leaked from another breach can do dramatically better than brute force, and this estimate does not model any of that.
How to use this calculator
- Enter the password length you’re considering.
- Toggle which character classes it will actually use.
- Read the entropy and the rough brute-force time estimate.
Frequently asked questions
Is a higher entropy number always a stronger password?
Only if the password is actually randomly generated. A high-entropy score describes the size of the space a brute-force search would have to cover — it says nothing about whether a specific password sits in the tiny fraction of that space attackers check first (common words, patterns, and previously leaked passwords).
Why does adding symbols increase entropy so much?
Because it enlarges the character-set size, and entropy grows with the logarithm of that size for every character in the password — a bigger set size means every single character contributes more bits, not just the ones that happen to be symbols.
Should I trust the exact crack-time figure shown?
Treat it as an order of magnitude, not a precise prediction — real attack speeds vary by many orders of magnitude depending on how the password is stored and hashed, and this estimate assumes one commonly cited rate.
Is a longer password always better than a more complex one?
Length generally matters more, because it’s a multiplier in the exponent, not just the base — a longer password using fewer character classes often beats a shorter one using more, even though both raise entropy through different levers.
What does NIST actually recommend for passwords?
NIST SP 800-63B’s current guidance emphasises length over complexity requirements, discourages mandatory periodic password changes (they tend to produce weaker, more predictable passwords), and recommends checking new passwords against lists of known-breached passwords — a different and more effective defence than entropy alone measures.