Skip to content

Password strength, measured properly

Why length beats complexity rules, how entropy is calculated, and what a generated password protects you from.

Last reviewed 8 September 2026

Most password advice is about the wrong thing. Sites demand a capital letter, a digit and a symbol, and users respond with Password1!, which satisfies every rule and is among the first guesses any attacker makes. The measure that actually matters is entropy, and it is straightforward to calculate.

What entropy means here

Entropy is the number of bits of genuine unpredictability in a password. For a randomly generated one it is:

bits = length × log₂(size of character set)

A sixteen-character password drawn from 92 possible characters has 16 × log₂(92) ≈ 104 bits. Each additional bit doubles the number of guesses required, so the scale is exponential: 104 bits is not twice as strong as 52 bits, it is about four thousand trillion times as strong.

The crucial qualifier is randomly generated. The formula describes the work an attacker faces when they know the character set and the length but nothing else. It says nothing about a password a human invented, because human choices are not uniformly distributed.

Why length beats complexity

Adding a character multiplies the search space by the size of the character set. Adding a character class only increases the base of a logarithm. The arithmetic is decisive.

PasswordCharacter setEntropy
8 characters, all four classes92≈ 52 bits
12 characters, lowercase only26≈ 56 bits
16 characters, all four classes92≈ 104 bits
20 characters, all four classes92≈ 130 bits

Twelve lowercase letters beat eight characters using every class. That is the whole argument for length, and it is why current guidance from NIST recommends dropping composition rules and allowing long passphrases instead.

Why a human-chosen password is weaker than it looks

Attackers do not iterate through every combination. They start with leaked password lists, then dictionary words, then predictable substitutions and appended digits. Tr0ub4dor&3 looks complicated and follows patterns a cracking rule set already encodes: capitalise the first letter, replace o with 0, append a symbol and a digit.

The same applies to personal information. A pet’s name, a birth year and a favourite team are all in the public record for most people, and targeted cracking uses exactly that.

What the attacks actually are

The threat model determines whether entropy matters at all.

  • Online guessing against a login form is slow and rate limited. Almost any non-trivial password survives it.
  • Offline cracking of a stolen password database is the case entropy addresses. Modern hardware tries billions of candidates per second against a fast hash, which is why the storage function matters as much as the password.
  • Credential stuffing takes passwords leaked from one breach and tries them everywhere else. Entropy is irrelevant here; only uniqueness helps.
  • Phishing collects the password directly. A 130-bit password typed into a convincing fake page is as compromised as a weak one.

Two of those four are not solved by a stronger password. That is why uniqueness per site and two-factor authentication do more for most people than adding characters.

How storage changes everything

When a database leaks, what protects the passwords is the function used to store them. A plain SHA-256 hash can be attacked at billions of guesses per second on commodity hardware. A deliberately slow function — bcrypt, scrypt or Argon2, with a per-user salt — reduces that to thousands. The same password can be trivially cracked or effectively safe depending entirely on a decision made by the site, which you cannot see or control.

This is worth understanding as a developer: if you are storing passwords, the choice of function matters more than any policy you impose on your users. A general-purpose hash from the hash generator is the wrong tool for that job, and it says so on the page.

Practical conclusions

  • Use a password manager and let it generate passwords. You will never type most of them, so memorability is irrelevant.
  • Use a different password everywhere. This defeats credential stuffing, which is the attack most likely to affect you personally.
  • Aim for 16 characters or more where the site allows it. Around 100 bits of entropy is far beyond any offline attack.
  • Turn on two-factor authentication for email and banking first. Email is the reset path for everything else.
  • Do not rotate passwords on a schedule. NIST now advises against it, because forced changes produce predictable variations.
  • For the few passwords you must remember — your device login and your password manager’s master password — use a long passphrase of several unrelated words.

The password generator on this site uses the browser’s cryptographic random number generator and shows the entropy of what it produced, so you can see the figure rather than a coloured bar.

Tools referred to in this guide