Password Entropy Calculator
Calculate password entropy, brute force time, and security strength. Measure password complexity and cryptographic strength.
About this calculator
Password strength against brute-force guessing comes down to a single number: how many possible passwords exist, expressed as entropy in bits. This calculator sizes the character set from whichever categories you enable — uppercase, lowercase, numbers, and symbols each add their own count of possible characters — then computes entropy as password length multiplied by the base-2 logarithm of that character set size, since each additional character multiplies the total number of possible passwords rather than just adding to it. Possible Passwords is that full count, character set size raised to the power of password length, which grows so explosively that even modest increases in length dwarf what adding another character category alone can achieve.
Brute Force Time estimates how long an attacker guessing at a billion attempts per second would need on average, using half the total possible passwords as the expected number of guesses before finding the right one — an attacker doesn't know the password in advance, so on average they'll stumble onto it partway through the full space, not always at the very end. Equivalent Key Length simply reframes entropy in the same units used for symmetric encryption key sizes, making it easy to compare a password's real-world strength against a familiar benchmark like AES-128.
Inputs
Results
Password Entropy
78.7 bits
Brute Force Time
7,540,500 years
Equivalent Key Length
78.7 bits
How to Use This Calculator
- Set the password length in characters.
- Select the character types used: uppercase, lowercase, numbers, and/or symbols.
- Review password entropy in bits -- aim for 72+ bits for most accounts, 120+ for high-security.
- Check the equivalent brute-force time in years at modern cracking speeds.
- Use these benchmarks to set minimum password requirements in your security policy.
How the result changes with Password Length
| Password Length | Password Entropy | Brute Force Time | Equivalent Key Length |
|---|---|---|---|
| 6 | 39.3 bits | 0 years | 39.3 bits |
| 9 | 59 bits | 9.08 years | 59 bits |
| 18 | 118 bits | 5,201,960,000,000,000,000 years | 118 bits |
| 30 | 196.6 bits | 2,475,720,000,000,000,000,000,000,000,000,000,000,000,000 years | 196.6 bits |
What each input means
- Password Length
- Length of password
- Character Set Size
- Number of possible characters (if not using checkboxes)
- Uppercase Letters
- Include A-Z
- Lowercase Letters
- Include a-z
- Numbers
- Include 0-9
- Symbols
- Include special characters
How this is calculated
Formula
Entropy = Length × log₂(Character Set Size)Worked example, using the default values
- Identify Input Parameters4 parametersPassword Length = 12, Character Set Size = 94, Uppercase Letters = 1, Lowercase Letters = 1 = 6 input(s) provided
- Calculate Password EntropyPassword Entropy78.7 = 78.7
- Calculate Brute Force TimeBrute Force Time7540500 = 7540500
- Calculate Equivalent Key LengthEquivalent Key Length78.7 = 78.7
- Calculate Possible PasswordsPossible Passwords4.7592e+23 = 4.7592e+23
Engine last updated . Checked against 6 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why is Character Set Size ignored once I turn on any of the character-type checkboxes?
The checkboxes let the calculator build the character set precisely from the categories you actually plan to allow, which is more accurate than a single manually entered number. Character Set Size only comes into play as a fallback when every checkbox is switched off, letting you model a custom or unusual character set that doesn't fit the standard four categories.
What does Equivalent Key Length mean if it's the same number as entropy?
It's intentionally the same figure, just framed in a more familiar context — cryptographic key sizes like AES-128 or AES-256 are described in bits of entropy, so expressing a password's strength the same way makes it directly comparable to well-known encryption benchmarks. A password with 80 bits of entropy is, in a rough brute-force sense, about as hard to guess as breaking an 80-bit symmetric key.
Does Brute Force Time assume an attacker has to try every possible password?
No — it uses half the total possible passwords as the expected number of attempts, reflecting that an attacker who doesn't know the password in advance will, on average, find it partway through searching the full space rather than always needing to exhaust every possibility. Some attacks get lucky early and some take longer than the full space would suggest, but the average lands at roughly half.
Why does adding a few extra characters increase entropy more than adding another character category?
Entropy scales as length times the logarithm of character set size, so length has a direct multiplying effect on the exponent while adding a character category only nudges the base of that exponent upward. Going from a 10-character to a 14-character password typically adds far more entropy than switching from lowercase-only to lowercase-plus-symbols at the same length.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
RSA Key Strength Calculator
Calculate RSA key strength, equivalent symmetric key length, brute force time, and security margins.
Cryptography & SecurityBrute Force Attack Time Calculator
Calculate brute force attack time, cost, energy consumption, and feasibility for cryptographic systems.
Technology & ComputingPassword Strength Calculator
Check how strong your password could be based on length and character types. See estimated time to crack.
Technology & ComputingSecurity Tools Calculator
Password strength analysis, crack time estimation, and hash algorithm comparison.
Cryptography & SecurityAttack Probability Calculator
Comprehensive cryptographic attack analysis. Brute force, birthday attacks, side-channel risks, password strength, and key derivation security.
More in Technology & Computing.