🧮 Password Entropy Calculator

Choose a character set and length to see the theoretical entropy (in bits) and an estimated offline crack time — useful for designing a password policy, not for checking a real password.

The formula, worked through

The boxes set the pool size R: 26 lowercase, 26 uppercase, 10 digits, 32 ASCII symbols - 94 with all four on. Crack times assume an attacker finds the password halfway through the search:

bits         = L x log2(R)
12 x log2(94) = 12 x 6.5546 = 78.7 bits
avg guesses   = 94^12 / 2   = 2.4 x 10^23
at 10^10/sec  = 754,000 years

Each extra character is worth another 6.55 bits. Turning symbols off drops the pool to 62 and the same 12 characters to 71.5 bits, so all the symbols together are worth about one extra character.

Reading the crack-time rows

This measures a policy, not a password. The maths holds only if every character was picked at random: Password1234! also scores 78.7 bits here and falls to a wordlist in seconds. Nothing you type leaves your browser.

Frequently asked questions

How many bits of entropy is a strong password?

Under 40 bits is trivially broken offline. 60 is a reasonable floor for an ordinary account behind a properly hashed database, and 80 or more for anything that unlocks other accounts. 12 random characters from all four sets gives 78.7.

How do you calculate password entropy?

Multiply the length by the base-2 logarithm of the character pool size: bits = L x log2(R). Eight characters drawn from all 94 printable ASCII symbols is 8 x 6.5546, or 52.4 bits - about three and a half days at ten billion guesses per second.

Is it better to add symbols or add length?

Length. Widening the pool from 62 to 94 adds 0.6 bits per character; one more character adds 6.55. Composition rules also push people towards predictable substitutions, which is why NIST dropped them.