Security Tools Calculator
Comprehensive security calculator for password strength analysis, entropy calculation, crack time estimation, and hash algorithm comparison. Essential for security-conscious users and developers.
About this calculator
This calculator bundles three related security tools around a single core idea -- entropy, the number of bits of genuine randomness in a secret. Password strength analysis computes entropy as length x log2(charset size): each added character multiplies the number of possible passwords by the charset size, and log2 of that product converts multiplication into a simple bit count, so entropy adds linearly as you add characters. Character variety and password length both raise entropy, but they don't raise it equally -- doubling the length always doubles entropy, while adding one more character CLASS (say, symbols on top of letters and numbers) only multiplies the charset size, which has a much smaller effect on the log2 term than length does.
That's why security guidance increasingly favors long passphrases over short, highly "complex" passwords: a 20-character lowercase-only passphrase can carry more entropy than an 8-character password stuffed with every character class. The time-to-crack estimates assume a brute-force attacker who must try roughly half the total keyspace on average before finding the right password, scaled by an assumed guesses-per-second rate that varies enormously by attack scenario -- a rate-limited online login form (around 100 guesses/sec) is a vastly harder target than an offline attacker who has stolen a password database hashed with a fast, unsalted algorithm (billions of guesses/sec on modern GPU hardware), which is why slow, purpose-built password-hashing algorithms like bcrypt and Argon2 exist: they deliberately throttle the offline attacker's guess rate down toward the online one.
Step 1 of 3
How to Use This Calculator
- Select Tool Type: Password Strength Analysis to evaluate an existing pattern, Password Generation Parameters to design secure credentials, or Hash/Encryption Info to compare algorithms.
- For strength analysis, set the Password Length and toggle the character types you use (Lowercase, Uppercase, Numbers, Symbols).
- Review the Entropy (bits), Strength Rating, and Time to Crack for both online (throttled) and offline (GPU) scenarios.
- For generation parameters, set your Target Entropy in bits (80+ for high security) and Preferred Length to see which charset and minimum length meets your goal.
- For hash info, select an algorithm (MD5, SHA-1, SHA-256, SHA-512, bcrypt, Argon2) and check Security Status and Recommended Use before implementing.
- Use the crack-time comparison table to see the impact of attack speed on password security.
What each input means
- Tool Type
- Calculation mode to use.
- Password Length
- Number of characters in the password.
- Lowercase (a-z)
- Include lowercase letters.
- Uppercase (A-Z)
- Include uppercase letters.
- Numbers (0-9)
- Include numbers.
- Symbols (!@#$...)
- Include special characters.
- Avoid Common Patterns
- Avoids dictionary words, sequences, repetition.
- Target Entropy (bits)
- Recommended: 80+ bits for high security.
- Include Ambiguous Chars
- 0, O, 1, l, I, |
How this is calculated
Worked example, using the default values
- Identify Input Parameters11 parametersTool Type = 0, Password Length = 12, Lowercase (a-z) = 1, Uppercase (A-Z) = 1, Numbers (0-9) = 1, Symbols (!@#$...) = 1, Avoid Common Patterns = 1, Target Entropy (bits) = 80, Preferred Length = 16, Include Ambiguous Chars = 0, Hash Algorithm = 2 = 11 input(s) provided
- Calculate Strength RatingStrong = Strong
- Calculate Online Attack TimeOnline Attack Time = crackTimes.onlineThrottled7.5e+4 billion years = 7.5e+4 billion years
- Calculate EntropyEntropy = 878.7 = 78.7
- Calculate Character Set SizeCharacter Set Size94 = 94
Engine last updated . Checked against 4 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why does password length matter more than character variety?
Entropy is length multiplied by log2(charset size), so length is a linear multiplier on the bit count while charset size only enters through a logarithm -- doubling the length always doubles entropy, but doubling the charset size (say from 47 to 94 characters) only adds about 1 extra bit per character. A long password built from a smaller character set can easily out-entropy a short one stuffed with every symbol, which is the reasoning behind passphrase-style password advice.
Why is the offline attack time so much shorter than the online one?
Online attacks are limited by how fast the target system will accept login attempts -- a well-configured server rate-limits guesses to roughly 100 per second or fewer. Offline attacks happen after an attacker has already stolen a password database; with no server to rate-limit them, they can run guesses at whatever speed their hardware allows, which for a fast unsalted hash on modern GPU clusters can reach into the trillions of guesses per second -- many orders of magnitude faster than any online login form would ever permit.
Why do bcrypt and Argon2 show as 'Recommended' when they're slower than SHA-256?
Being slow is the entire point for password hashing, not a weakness -- SHA-256 is deliberately fast because it was designed for data integrity checks, which makes it a poor fit for passwords since a fast hash lets an offline attacker try billions of guesses per second. bcrypt and Argon2 are intentionally slow (and Argon2 also memory-hard) specifically to throttle an attacker's guess rate down to something much closer to an online attack's speed, even after a database breach.
Does adding a fifth or sixth character class keep helping as much as the first few?
Not proportionally -- each additional character class (lowercase, uppercase, numbers, symbols) only multiplies the charset size, and because entropy scales with log2 of that size, each successive class adds a shrinking number of bits rather than a fixed amount. Going from letters only to letters+numbers helps meaningfully; adding symbols on top helps less in absolute bit terms than going from length 8 to length 16 would.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Password Strength Calculator
Check how strong your password could be based on length and character types. See estimated time to crack.
CybersecurityPassword Generator
Generate secure random passwords with customizable length and character sets. See password strength and entropy.
Cryptography & SecurityPassword Entropy Calculator
Calculate password entropy, brute force time, and security strength. Measure password complexity and cryptographic strength.
Technology & ComputingHash Properties Calculator
Compare cryptographic hash function properties. See output size, collision resistance, brute force time, and security status for MD5, SHA-1, SHA-256, SHA-512, and bcrypt.
Technology & ComputingBinary/Hex/Decimal Converter
Convert a decimal number into its binary, octal, and hexadecimal representations. Includes bit count, byte size, and ASCII character lookup.
More in Technology & Computing.