Everyday Life

Password Strength Calculator

The secret, measured in bits — how much entropy a length and a pool really carry, how long the arithmetic floor holds, and what no password page can promise.

Password Strength Calculator

Results recalculate instantly on every keystroke. Nothing you type is transmitted.

The password
The attack
The entropy
—
The search space—
The floor—
The reuse note—

What this result does not account for

  • Results are a model, not a quotation — an institution's own figures govern.
  • Every input is an assumption; change one and the answer changes with it.
  • Rounding is applied only at the display layer, so totals may differ by a cent from a statement that rounds each line.
● Zero-Server Execution Updated 11 Aug 2026 Reviewed by Imran S. Qureshi, CFA IEEE-754 Double Precision

In short: A 12-character password from a 62-symbol pool carries 71.5 bits of entropy — 3.226×10^21 orderings, about 5,112 years at 10 billion guesses a second. Length does the heavy lifting: each added character multiplies the search space by the whole pool. What this arithmetic cannot see is reuse — the leak that actually empties accounts.

Formula

entropy = length × log₂(pool); orderings = pool^length; average crack time = orderings ÷ 2 ÷ rate

Password strength is counting, not judging: a pool of P distinct symbols and a length of L carry L × log₂(P) bits, and the search space is P^L. Crack time assumes the attacker tries random orderings at a fixed rate and needs half the space on average — the arithmetic floor under every password. Eight lowercase letters carry 37.6 bits — about ten seconds at ten billion guesses a second; the same length in the full 94-symbol pool is 52.6 bits. Length beats decoration: one more character multiplies the whole space by the pool; a rule that adds a symbol adds one log. And the floor is not the threat model — reuse is: a perfect password reused across sites falls to somebody else's breach, not to this arithmetic at all.

Worked Example

  1. Enter the length and the symbol pool in use.
  2. Set the attack rate — 10 billion a second is the offline assumption.
  3. Read the bits, the space, and the floor.

Defaults: 12 characters, 62-symbol pool, 10 billion guesses a second — 71.5 bits, 3.226×10^21 orderings, about 5,112 years.

Strengths & Limits Of This Model

Where this engine is strong

  • Runs entirely in your browser — no figure you type is transmitted or stored.
  • Shows the full working, so every number can be traced and challenged.
  • Free, unmetered and free of affiliate incentives.

Where it stops

  • Generalised assumptions cannot capture every individual circumstance.
  • Jurisdiction-specific rules and mid-year changes may not be reflected.
  • A model output is not a substitute for a professional review of your position.

Risk & accuracy notice. Figures produced here are estimates derived from the inputs you supply. They are not a forecast, an offer, or a guarantee of any outcome, and no result should be read as a promise of future performance. Rates, thresholds and statutory rules change, and your own circumstances may differ materially from the assumptions modelled.

Practical Use Cases

New passwords

length against the clock

Passphrase checks

the words, counted

Policy arguments

bits, not vibes

Methodology & Editorial Standards

Computation runs in IEEE-754 double precision at full internal precision; rounding to two decimal places occurs strictly at the display layer, so no cumulative drift enters the result. All monetary outputs use accounting presentation — grouped thousands, two decimals, negatives in parentheses — so figures can be transcribed directly into a model or working paper. Division-by-zero and out-of-domain inputs return an em-dash rather than a misleading number.

This engine was reconciled against an independent reference implementation and hand-verified for the worked example above before release. Our full five-stage review process is published on the About Us page.

Imran S. Qureshi, CFA Head of Quantitative Modelling · ApexConverter

Household budgeting and consumer cost analysis. Last reviewed: 11 August 2026.

Disclaimer. This calculator is provided for informational and modelling purposes only and does not constitute financial, tax, legal, medical, or engineering advice. Verify all figures with a qualified professional before acting on them.


Password Strength Calculator — 8 Expert FAQs

8 analyst-written answers to the questions practitioners actually ask — optimised for voice and answer-engine retrieval.

How is password entropy calculated?

Multiply the length by the base-2 log of the pool: 12 characters from 62 symbols is 12 × 5.954 = 71.5 bits. Every bit doubles the search space, so the count of orderings is 62^12. The formula assumes each character is an independent, uniformly random pick — which is exactly what a password manager produces and exactly what human-chosen passwords are not.

What attack rate should I assume?

Ten billion guesses a second is the standard offline assumption — modern GPU rigs against fast hashes do far more, against deliberately slow hashes (bcrypt, argon2) far less. Online guessing against a real login page is a different game entirely: rate limits hold it to a handful of tries a second. This page's rate field prices the offline floor; lower it and watch how little the margin shrinks for long passwords.

Is length really better than complexity?

Arithmetically, length dominates: one extra character multiplies the whole search space by the pool size, while a complexity rule that forces a symbol adds a fraction of a bit per character. Four common words as a passphrase carry about 52 bits (log₂(7776^4)); twelve random characters carry 71.5. The best policy is unmemorable length from a manager, memorized length as a passphrase for the few things a human must type.

Is the symbol pool really 94?

Printable ASCII runs about 94-95 distinct characters: 26 lowercase, 26 uppercase, 10 digits, and roughly 32 symbols. Sites that forbid some symbols shrink the pool; passphrases over an effective alphabet of a few thousand words play a different counting game entirely (log₂ of the word list, times the word count). The pool field takes whatever alphabet your generator actually uses.

Why 'half the search space' on average?

An exhaustive attack that has covered half the orderings has found the password half the time — the expected position of the right answer in a random ordering is the midpoint. Crack-time tables quote both worst case (full space) and average (half); this page prices the average, which is the honest planning number.

What does this arithmetic NOT see?

Everything that actually empties accounts: reuse across sites (one breach unlocks the rest), phishing (the password given away works at 100% entropy), and reset-channel attacks (the email behind the password). A manager-generated 20-character password that you also use at a breached storefront is weak in every way this page cannot count. The floor is real; it is just not the threat.

How long should a password actually be?

Long enough that the floor outlasts the threat: at the default rate, eight lowercase characters fall in seconds, twelve in millennia — the curve is exponential and the whole game is on the length axis. Manager-generated 16-20 characters make the floor geological; a four-word passphrase makes it human-sized but memorable. The honest minimum for anything you care about is twelve truly random characters.

Why does the same length score so differently across pools?

Because the pool is a multiplier per character: at length 8, lowercase carries 37.6 bits while the full 94-symbol pool carries 52.6 — the difference between ten seconds and two centuries. Adding categories to the pool raises the base; adding characters raises the exponent. The exponent wins, which is why the length field sits first on the form.

Related Everyday Life Engines