Password Entropy & Crack Time Estimator
Type a password to see its strength in bits of entropy and realistic crack time estimates — for online guessing, offline bcrypt, and raw hash attacks. Patterns like keyboard walks and dictionary words are flagged with plain-English explanations. Nothing is sent anywhere.
Enter Password
Evaluated entirely in your browser. Nothing is sent to any server.
Strength Analysis
Estimated Crack Times
| Attack scenario | Time to crack |
|---|
Weaknesses Detected
Generate a Strong Password
Generate a random password and see its strength instantly.
Learn more: how password entropy and crack times are estimated
Entropy comes from pool size and length
The tool works out entropy in bits as length x log2(pool size). The pool is the number of possible characters at each position: 26 for lowercase, 26 for uppercase, 10 for digits and 33 for symbols, which makes 95 when all four appear. One truly random character from 95 adds about 6.6 bits. A 12-character password drawn at random from that pool is 78.8 bits.
Length also beats variety once the pool is reasonable. Twelve random lowercase letters are 56.4 bits. Making them lowercase letters and digits lifts that to 62.0 bits, while adding one more lowercase letter gives 61.1 bits. Both help, and a longer password helps without constraining what you type.
The formula assumes every character was picked at random. People do not pick that way. Troy Hunt's piece on password strength meters argues that meters running simple maths in the browser mislead users because they know nothing of human behaviour. His example is "Passw0rd!", which scores as strong but appears in any password dictionary worth its salt. The tool scores that password at 59.1 bits for the same reason, and then flags the keyword and the leet-speak substitution.
Crack times depend on the attack
The tool assumes an attacker finds the password after trying half the possibilities, 2^(bits - 1) guesses, and divides by a guess rate. It uses four rates: 1,000 guesses a second for online guessing, 10,000 for offline bcrypt, 10 billion for offline SHA-256 and 100 billion for offline MD5.
A public hashcat benchmark of an RTX 4090 (Chick3nman's gist) lists 164.1 GH/s for MD5, 21.98 GH/s for SHA2-256 and 184.0 kH/s for bcrypt, so the tool's rates are in the same range for one fast GPU. The bcrypt figure depends on the cost setting, so a real service may be slower or faster.
At 100 billion guesses a second, a 59.1-bit password such as "Passw0rd!" takes about 36 days to try half its space, and a random 78.8-bit one takes millions of years. The hash a service uses matters as much as your password, because the same password can survive a slow hash and fall quickly to a fast one.
The generated passphrase
The passphrase button picks 7 words at random from the EFF short wordlist of 1,296 words, using the browser's secure random generator. That is 7 x log2(1,296), or 72.4 bits. The tool uses that figure for it and not the character formula, which would overstate a word-based phrase. The random-password button draws each character the same way from an 80-character set.
FAQ
Is a longer password always better than a more complex one?
For random characters, each added character adds log2(pool) bits, while widening the pool only slightly increases that per-character figure. Twelve random lowercase letters give 56.4 bits, and adding digits to the set gives 62.0, against 61.1 for one extra lowercase letter.
Why did the tool flag a password that has numbers and symbols?
Variety does not hide a pattern. The tool checks for keyboard walks, common words, leet-speak substitutions, repeated characters and short length, and flags them whatever pools the password uses.
What makes a passphrase strong?
Random word choice and enough words. The entropy is the number of words times log2 of the list size, so seven words from a 1,296-word list is 72.4 bits. Words you pick yourself carry far less, since people favor common words and patterns.