Password entropy calculator

Entropy of a uniformly random sequence and a search model at the supplied rate.

Inputs

Password entropy calculator

3 fields

Check the measurement units shown in or near the field.

Assumed verification speed in billions of attempts per second: 1 = 10⁹ attempts/s. This is a scenario value, not a measured attack speed.

Educational uniform-independent-generation model, not a real-password assessment or attack-time guarantee. No actual password is needed. Results outside the finite numerical range are rejected.

Fill in the fields and the result will appear here automatically.

An educational model of uniform independent character generation from the selected full alphabet. It shows search-space entropy and approximate exhaustive-search time at a manually supplied rate. No actual password is required: its contents, breaches and account security are not checked. For a human-chosen password, length and alphabet size do not determine its actual entropy.

FAQ
4 questions
Freshness
formula-based

How it works

Formula and logic

For length L and N equiprobable independent characters, possibilities M=N^L and entropy H=log₂M=L·log₂N. Length is a positive safe integer; rate r is in billions of attempts/s. Displayed time is M/(2·r·10⁹), a midpoint approximation for a large space. The exact expected count for a nonrepeating exhaustive search including success is (M+1)/2; independent random guesses with replacement require M on average. Alphabet 94 means printable ASCII without space. One displayed year is 31,557,600s.

Example

Twelve characters from letters and digits give 71.45 bits and about 3.2·10²¹ combinations.

Fields and units

  • Random sequence length — characters
  • Character set — list option
  • Verification rate — 10⁹ attempts/s

How to use

  • — Set the integer length of the randomly generated sequence.
  • — Select the complete alphabet available to each independent draw, not the characters observed in an existing password.
  • — Supply the assumed rate in billions of attempts/s and interpret the result only within this model.

Method and limitations

Calculation method
Formula and logic
Limitation
Educational uniform-independent-generation model, not a real-password assessment or attack-time guarantee. No actual password is needed. Results outside the finite numerical range are rejected.

FAQ

How many bits guarantee password safety?

No number here guarantees safety. H describes only the stated random generation model. Time depends on hash verification cost, rate limits, breaches and other threats; this tool does not measure the rate.

Why does search time use half the space?

For a large uniform space the tool uses M/2. Exact nonrepeating search including success averages (M+1)/2: one random digit takes 5.5 attempts, while this approximation shows 5. The model is explicitly approximate.

How can length and alphabet size be compared?

One additional random character adds log₂N bits. Changing N to N₂ adds L·log₂(N₂/N). Compare particular choices under the same generation model, not all human-selected passwords.

Can this test passphrases or dictionary attacks?

No: the interface contains six character alphabets, not a word dictionary or password text. Random-word generation needs a separate model. Predictable phrases, reuse and breaches are not assessed.