What Is Entropy, and What Makes a Password Strong?
Contrary to intuition, a password's strength isn't measured by how complex it looks, but by how many different possible combinations it could have been drawn from. This measure is called entropy, and it's computed roughly as length × log2(character pool size) — expressed in bits. Every extra bit doubles the number of possible combinations; so as both the password's length and the variety of character types used (lowercase/uppercase, digits, symbols) increase, guessing it at random becomes exponentially harder.
Length matters more than complexity: an 8-character password made only of lowercase letters has 26⁸ (~208 billion) possible combinations, while going to 16 characters with the same character pool raises that number to 26¹⁶ (~4×10²²) — a gain of billions of times. Adding symbols and uppercase letters helps too, but a few extra characters usually gain you more.
The "estimated crack time" on this tool is meant only to give you a sense of scale, based on one assumption: a determined attacker capable of 10 billion guesses per second against a stolen password database (hashed or not). In the real world this time can range from seconds to centuries depending on how the target system stores passwords — so the number shown here isn't a guarantee, it's a relative comparison tool.
Practical tip: generating a separate, random password for every account and storing it in a password manager (1Password, Bitwarden, etc.) solves length, variety, and "reusing the same password" risk all at once. You can also try our own generator — Password Generator.
Try This Next
Finished here? These might be your next step.
Frequently Asked Questions
length × log2(character pool size). Every extra bit doubles the number of possible combinations; so as both length and the variety of character types used (lowercase/uppercase, digits, symbols) increase, brute-forcing the password becomes exponentially harder. The score and "crack time" estimate on this tool are based on exactly this calculation.localStorage/sessionStorage, and it's never sent to analytics tools. If you close the tab or refresh the page, the password you typed is permanently lost.Last updated: