Password strength and entropy calculator
See how many bits of entropy a password or passphrase carries and how long it could take to find at the attack speed you choose. Common patterns (sequences, repeats, keyboard runs, very short, common passwords) are flagged. Everything runs in your browser; the password never leaves your device.
Do not type your real password; use a trial password of similar structure. The fields do not leave your browser, but typing real passwords into third-party pages is not a good habit.
Length and character types determine the result. Type a sample of the same length and structure instead of your real password.
The speed at which an attacker is assumed to try a leaked password hash offline. The real speed varies widely with the hash algorithm and hardware.
Random password generator
The password is generated from your browser's secure random number generator (crypto.getRandomValues). Each character is chosen independently and uniformly; rejection sampling avoids bias. The generated password is not sent or stored anywhere.
O, 0, I, l, 1, | and quote-like characters are left out; useful for passwords typed by hand.
Satisfies some systems' complexity rules; lowers entropy very slightly.
Results
Enter a trial password. For a passphrase you need at least one word and a list size of at least 2 (a whole number).
Calculation and assumptions
- Pool entropy = length × log2(pool). Pool: lowercase 26, uppercase 26, digits 10, symbols and space 33, +100 for other characters (assumption).
- Passphrase entropy = number of words × log2(list size); the words must be chosen at random.
- Pattern penalty: sequence, repeat and keyboard runs count as one character of information; a password on the common list ≈ log2(list length) bits.
- Average guesses = 2^(bits − 1), worst case = 2^bits; time = guesses / (guesses per second).
The password you type and the one you generate stay in your browser's memory only; they are not sent to a server, not saved and not written to cookies or local storage.
This is an estimate. Real attackers use dictionaries, rules, personal details and leak lists; the common password list in this tool is a small sample. Entropy depends on how the password was chosen: a password a person comes up with is far weaker than a random one of the same length. For critical accounts use a password manager, unique passwords and multi-factor authentication.
Shall we review your organisation's password policy, authentication infrastructure and OT/SCADA access management together?
Request a meeting01
How to use
A
Choose what to analyse: a password based on a character pool or a passphrase of random words. Type a trial password of similar structure instead of your real one.
B
Choose the attack speed; read the entropy, average and worst-case crack time and the pattern warnings.
C
If you need a strong password, use the random password generator below and save the result in your password manager.
02
What is entropy and how is it calculated?
Entropy is the base-2 logarithm of the number of guesses needed to find a password (bits). For a randomly chosen password in which each character is drawn independently from the pool, entropy is length × log2(pool size). A random 12-character password drawn from a 95-character pool carries about 79 bits; a 4-digit PIN only about 13 bits.
Each extra bit doubles the number of guesses: 10 more bits means roughly a thousand times as many guesses. That is why length is usually more effective than diversifying character types.
03
Attack speed and assumptions
Crack time rests on the assumption that an attacker tries a leaked password hash offline; you choose the speed. Slow, well-tuned key derivation functions cut the speed sharply, while fast hash algorithms allow very high speeds on strong hardware. The four values in the tool are example assumptions, not measurements.
The 'average' time in the calculation is trying half the space; 'worst case' is the whole of it. In online attacks (a login form) rate limiting and account lockout apply; this tool does not model that. The result is an upper bound for a password that was truly chosen at random and contains no pattern.
04
Password versus passphrase
A passphrase of random words is an easy-to-remember option at the same entropy: each word drawn at random from a list of 7776 adds about 12.9 bits; six words come to about 78 bits. But the words must be picked with dice or a secure random number generator; words you choose yourself, sayings or song lyrics come nowhere near this value.
Current authentication guidance (such as NIST SP 800-63B) puts length, checking against leak lists and multi-factor authentication ahead of complexity rules. Using a separate password for every service and a password manager can matter more than the strength of any single password.
FAQ
- Is the password I type sent anywhere?
- No. The calculation runs entirely in code in your browser; the password is not sent to any server, not saved and not written to cookies or local storage. Even so, we recommend typing a trial password of similar structure rather than your real one.
- Why can my password rate 'strong' yet be on a common list?
- The common password list in this tool is a small sample of one hundred entries. Real attackers have lists compiled from leaks with billions of entries. Even if the tool finds no pattern, it cannot guarantee the password is safe.
- Which attack speed should I choose?
- To think about defence in the worst case, choose the high values that assume a fast hash algorithm and strong hardware; choose a low value if you know your passwords are stored with a slow, well-tuned key derivation function. If unsure, base your decision on the high value.
- Is the random password generator safe?
- The generator uses the browser's secure random number generator (crypto.getRandomValues) and applies rejection sampling to avoid modulo bias. The generated password is not sent anywhere. Still, save it in a password manager and do not reuse it elsewhere.
- Is entropy enough by itself?
- No. A password being unique (not reused elsewhere), absent from leak lists and protected by multi-factor authentication on the account matter at least as much as entropy.
Are your password policy and access management up to date?
Let us review authentication, network segmentation and OT/SCADA remote access security together. In a free discovery call we discuss your current state and targets.