Computer science
How strong is your password: entropy and time to crack
Type a password and see how many bits of entropy it really has, how long it would take to guess and which patterns weaken it. Or generate a random one. Nothing is sent or saved.
The password stays in this tab: it does not go over the network, into the page address or into saved results.
Type a password to check it.
Generate a random password
What makes a password strong
A password's strength is measured in bits of entropy: how many guesses, at most, it takes to find it. Each character picked at random from the 26 lower-case letters adds about 4.7 bits, from all 94 printable symbols 6.6. Twelve random characters of every kind make almost 79 bits, hundreds of billions of billions of combinations.
But people do not choose at random, and attackers know it: they try leaked passwords first, dictionary words with a capital and a number at the end, dates, keyboard runs. That is why the estimate here takes bits off for every recognised pattern instead of just counting characters.
The time then depends on how the password is stored. A site that limits login attempts allows only a few per second; if the database is stolen, the attack happens offline, and with a fast hash a graphics card tries billions of passwords per second. The best defence is still a long, random password, different for every site, kept in a password manager.
Common mistakes
- Swapping letters for look-alike digits, as in P4ssw0rd: it is the first variant attacks try.
- Reusing the same password on several sites: one breached site exposes all the others.
- Preferring a short, complicated password to a long, simple one: length counts for more than variety of symbols.
Frequently asked questions
How many bits does a safe password need?
For an online account protected by attempt limits, about 40 to 50 bits is enough; to withstand a stolen database, at least 70 to 80. A phrase of five or six random words or 14 random characters gets there.
Is the password I type here sent anywhere?
No. The calculation runs in your browser; the page does not put it into the address or into saved results and does not transmit it. You can check by going offline: it keeps working.
Are the generated passwords truly random?
Yes: they use the browser's cryptographic generator, the same one secure connections use, with sampling that favours no character.
How this calculation works
Ideal entropy = length × log₂(possible symbols), with 26 lower case, 26 upper case, 10 digits, 33 symbols and 100 for other characters. Each character that repeats the previous one or continues a sequence is worth 1 bit instead of log₂(symbols); a common word is worth about 14 bits, a year about 7. Average time = 2^entropy ÷ 2 ÷ guesses per second.
Related calculators
Hash generator
MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of a text or of bytes, with a hash checker.
Base64 converter
From text, integer, hexadecimal or binary to Base64 and back, with the 6-bit groups explained.
Unix timestamp converter
From Unix timestamp to date and time and back: seconds, milliseconds, UTC and local time.