- Home
- Tech & Screens
- Password Entropy Calculator
Password Entropy Calculator
Entropy measures how hard a password is to guess, in bits. Enter the length and tick the character sets it draws from to get the entropy, the number of possible passwords and how long a brute-force attack would take at the guessing speed you choose.
- Character pool
- 62 characters
- Possible passwords
- 3.23 × 10^21
- Average time to crack
- 5.11 thousand years
- Time to try every possibility
- 10.2 thousand years
- Rating
- Strong
Saved setups
Save a set of inputs you reuse — your usual rate, your loan, your room sizes — and load it back in one tap.
Your recent calculations
Results you calculate here are kept on this device so you can come back to them.
Formula
How to use it
- Enter the password’s length.
- Tick each character set it can contain.
- Choose a guessing rate that matches the threat you have in mind.
- Read the entropy and the average time to crack.
Worked examples
12 random letters and digits (62 possible characters) against 10 billion guesses a second
- Entropy
- 71.5 bits
- Character pool
- 62 characters
- Possible passwords
- 3.23 × 10^21
- Average time to crack
- 5.11 thousand years
- Rating
- Strong
8 random characters from all 94 against 10 billion guesses a second
- Entropy
- 52.4 bits
- Character pool
- 94 characters
- Possible passwords
- 6.1 × 10^15
- Average time to crack
- 3.53 days
- Rating
- Fair
A 6-digit PIN against 1,000 guesses a second: 500,000 tries on average
- Entropy
- 19.9 bits
- Character pool
- 10 characters
- Possible passwords
- 1,000,000
- Average time to crack
- 8.33 minutes
- Time to try every possibility
- 16.7 minutes
- Rating
- Weak
This only holds for random passwords
The formula assumes every character was chosen at random, as a password manager does. A password built from words, names, dates or keyboard patterns — “Summer2024!” — has far less real entropy than its length suggests, because attackers try likely patterns first. Do not type a real password into any web page to test it; only its length and character types are needed here.
What the guess rates represent
An online attack against a login form is limited by the server to a trickle of attempts. An offline attack on a stolen password database is limited only by hardware and by how the passwords were hashed: billions of guesses a second against fast, outdated hashes, but only thousands against slow, purpose-built ones such as bcrypt or Argon2. The rates offered are round figures for comparison, not measurements.
Length beats complexity
Each extra bit doubles the work. Adding symbols to an 8-character password lifts it from about 48 to 52 bits; making an all-lowercase password 16 characters long gives 75 bits. The ratings shown — weak under 40 bits, fair to 60, strong to 80, very strong beyond — are this calculator’s own rough guide.
Questions people ask
How many bits of entropy does a 12-character password have?
About 71 bits if it is random letters and digits (62 possibilities each), or about 79 bits using all 94 printable characters.
How long would it take to crack an 8-character password?
With all 94 characters there are about 6.1 × 10^15 possibilities. At 10 billion guesses a second that takes about 3.5 days on average.
How much entropy does a passphrase have?
Each word chosen at random from a 7,776-word Diceware list adds about 12.9 bits, so a five-word passphrase has about 64.6 bits.