Password entropy calculator
Entropy of a uniformly random sequence and a search model at the supplied rate.
Fill in the fields and the result will appear here automatically.
An educational model of uniform independent character generation from the selected full alphabet. It shows search-space entropy and approximate exhaustive-search time at a manually supplied rate. No actual password is required: its contents, breaches and account security are not checked. For a human-chosen password, length and alphabet size do not determine its actual entropy.
How it works
Formula and logic
For length L and N equiprobable independent characters, possibilities M=N^L and entropy H=log₂M=L·log₂N. Length is a positive safe integer; rate r is in billions of attempts/s. Displayed time is M/(2·r·10⁹), a midpoint approximation for a large space. The exact expected count for a nonrepeating exhaustive search including success is (M+1)/2; independent random guesses with replacement require M on average. Alphabet 94 means printable ASCII without space. One displayed year is 31,557,600s.
Example
Twelve characters from letters and digits give 71.45 bits and about 3.2·10²¹ combinations.
Fields and units
- Random sequence length — characters
- Character set — list option
- Verification rate — 10⁹ attempts/s
How to use
- — Set the integer length of the randomly generated sequence.
- — Select the complete alphabet available to each independent draw, not the characters observed in an existing password.
- — Supply the assumed rate in billions of attempts/s and interpret the result only within this model.
Method and limitations
- Calculation method
- Formula and logic
- Data or methodology source
- NIST SP800-63B-4: limits of password assessment
- Limitation
- Educational uniform-independent-generation model, not a real-password assessment or attack-time guarantee. No actual password is needed. Results outside the finite numerical range are rejected.
FAQ
How many bits guarantee password safety?
No number here guarantees safety. H describes only the stated random generation model. Time depends on hash verification cost, rate limits, breaches and other threats; this tool does not measure the rate.
Why does search time use half the space?
For a large uniform space the tool uses M/2. Exact nonrepeating search including success averages (M+1)/2: one random digit takes 5.5 attempts, while this approximation shows 5. The model is explicitly approximate.
How can length and alphabet size be compared?
One additional random character adds log₂N bits. Changing N to N₂ adds L·log₂(N₂/N). Compare particular choices under the same generation model, not all human-selected passwords.
Can this test passphrases or dictionary attacks?
No: the interface contains six character alphabets, not a word dictionary or password text. Random-word generation needs a separate model. Predictable phrases, reuse and breaches are not assessed.