Password Strength
Estimate password strength in bits of entropy and guess time.
Estimate the entropy and strength of a password. Free, offline, runs in your browser. Read more Show less
What is password entropy?
Entropy measures the size of the space an attacker would have to search, expressed in bits. Each additional bit doubles the number of possible passwords. A password drawn uniformly from 94 printable ASCII characters has about 6.57 bits per character. A password drawn from a 7,776-word list (like the EFF long word list) has about 12.9 bits per word.
Estimating entropy accurately requires knowing how the password was generated. This tool makes a conservative estimate: it counts the size of the character classes present and treats every character as if it were drawn independently. It does not model dictionary attacks or pattern-based cracking (which would lower the estimate).
How to use
Type or paste a password. The tool shows the estimated entropy, the classes present, and how long a fast offline attack (10 billion guesses per second) would take. This is a defense against brute force only.
FAQ
Is my password sent anywhere?
No. Everything runs in your browser. Nothing is logged or stored.
Why does my "complex" password show low entropy?
If it uses only lowercase letters and digits, the character pool is small. Real entropy comes from length and the number of distinct symbols available.
Does this estimate dictionary attacks?
No. Dictionary and pattern attacks are much faster than brute force. A random string like Tr0ub4dor looks complex but is predictable to an attacker using a rule-based cracker. This tool is a lower bound.
What entropy should I aim for?
60 bits resists a well-funded attacker for years. 80 bits is beyond foreseeable brute-force capability. 100+ bits is future-proof.