StatGardenREF. DESK
Calculators/Everyday/Password strength
Everyday

Password strength calculator

Entropy in bits and how long a brute force would take.

Published 6 August 2026 · Updated 24 September 2026

What this calculator does

Password entropy measures how many guesses a brute-force attack would have to make, expressed in bits. Each extra bit doubles the work. The formula is length multiplied by the base-two logarithm of the character set size, so a 12-character password drawn from all 94 keyboard characters carries about 78.7 bits.

Length matters far more than variety, and the numbers make the case better than the advice does. A 12-character lowercase-only password carries 56.4 bits, while an 8-character password using the full keyboard carries only 52.4 bits. The longer, simpler one is the stronger of the two, which is why passphrases have replaced the old rules about symbols and mixed case.

The formula

FormulaEntropy = length × log₂(character set size); average time to crack = 2^(entropy−1) / guesses per second

Entropy is the password length multiplied by log base 2 of the character set size, which gives the number of bits needed to describe one password out of all the possibilities. The average time to crack assumes the attacker searches half the space before finding it, so it is two to the power of one less than the entropy, divided by the guess rate you enter.

TermMeaning
EntropyThe number of bits of randomness in the password. Each additional bit doubles the number of guesses required.
Character setHow many distinct characters the password could have drawn from: 26 for lowercase, 94 for the full printable keyboard.
Guesses per secondHow fast the attacker can test candidates, which depends entirely on how the password was stored.
Brute forceTrying every possibility in turn. Entropy only describes resistance to this, not to guessing informed by knowing something about you.

The inputs explained

FieldWhat to enter
Password lengthHow many characters long the password is.
Character setThe pool the characters were drawn from. Choosing a larger pool than the password actually used overstates its entropy.
Guesses per second an attacker managesGuesses per second. Ten billion is a reasonable figure for an offline attack on a fast but poorly chosen hash; a well-chosen one is orders of magnitude slower.

When to use it

Comparing a longer password against a more complex one

The usual question is whether to add characters or add symbols. Running both versions settles it numerically, and length almost always wins by a wide margin.

Setting a minimum length for a policy

The length needed for 80 bits, shown alongside, gives a defensible minimum for whichever character set a policy is going to require in practice.

Understanding what a breach exposes

The same password is enormously harder or easier to crack depending on how the service stored it. Changing the guess rate shows how much of the protection came from the hashing rather than from the password.

Worked examples

Every figure in the tables below is produced by this page’s own calculator at build time, so the numbers and the tool always agree. Select any row to load that scenario.

How much does each extra character add?

The same character set at a range of password lengths.

Full keyboard, 94 characters, at ten billion guesses per second
LengthEntropyAverage time to crackRating
8 characters52.4 bits3.5 daysModerate
10 characters65.5 bits85.5 yearsStrong
12 characters78.7 bits7.55e+5 yearsStrong
16 characters104.9 bits5.90e+13 yearsVery strong
20 characters131.1 bits4.60e+21 yearsVery strong
Eight characters falls in 3.5 days at this guess rate. Ten characters takes 85.5 years, and twelve takes 755,000 years. Each character multiplies the search by 94, which is why the column climbs so violently: the gap between 8 and 12 is not 50% more work, it is roughly 78 million times more.

Does a bigger character set beat a longer password?

A fixed length of twelve characters drawn from each of the available character sets.

Twelve characters, four different pools
Character setEntropyAverage time to crackLength needed for 80 bits
Lowercase (26)56.4 bits55.2 days18 characters
Upper and lower (52)68.4 bits620.4 years15 characters
Letters and digits (62)71.5 bits5.12e+3 years14 characters
Full keyboard (94)78.7 bits7.55e+5 years13 characters
Widening the pool from 26 to 94 characters adds about 22 bits at this length, a real gain but a modest one next to what length buys. Note the last row of the previous table against the first row here: twelve lowercase characters carry 56.4 bits, comfortably more than the 52.4 bits of an eight-character password using every symbol on the keyboard.

Questions

Does high entropy mean my password is actually safe?

Only if it was generated randomly. The formula assumes every character was an independent draw from the pool. A password built from a dictionary word, a name and a year has a tiny fraction of the entropy its length and character set suggest, because an attacker guesses patterns rather than characters. Entropy describes generated passwords, not chosen ones.

What guess rate should I assume?

It depends on how the service stored the password, which you generally cannot know. Ten billion a second is a reasonable figure for an offline attack against a fast general-purpose hash. A password hashed properly with a slow, memory-hard function can be thousands or millions of times slower to attack, and an online login with rate limiting is slower still by a wide margin.

How many bits are enough?

Around 80 bits is the usual working answer for something that needs to hold up against an offline attack, and the calculator shows the length that reaches it for each character set. Below 60 bits is weak against anyone determined. The threshold moves with hardware over time, so treat it as a rule of thumb rather than a line.

Are passphrases really stronger than complex passwords?

Usually, and for the reason the second table shows: length is worth more than variety. A passphrase of several randomly chosen words is both long and genuinely random, provided the words are picked by something other than you. The entropy comes from the number of words and the size of the word list, not from the character count.

For converting text between characters and their numeric codes, see the ASCII converter. For a classical cipher and why it offers no real protection, see the Caesar cipher calculator.