How this calculator works
| Metric | Formula |
|---|---|
| Random characters | entropy = length × log₂(character set size) |
| Random passphrase | entropy = words × log₂(7,776) |
| Average time to crack | 2^entropy ÷ 2 ÷ guesses per second |
| Character set sizes | lowercase 26, uppercase 26, digits 10, symbols 33 |
Worked example
With these inputs:
- Password type: Random characters
- Length (characters): 12
- Character types used: Lowercase (a–z), Uppercase (A–Z), Digits (0–9), Symbols (!@#…)
- Words in passphrase: 5
- Attack scenario: Stolen hashes, slow hash e.g. bcrypt (100,000/second)
Average time to crack: longer than the age of the universe. A random 12-character password from 95 characters has 78.8 bits of entropy. Average time to crack: longer than the age of the universe — stolen hashes, slow hash e.g. bcrypt (100,000/second).
| Entropy | 78.8 bits |
|---|---|
| Character set size | 95 characters |
| Possible combinations | ≈ 10^23.7 |
| Average time to crack — online attack, rate-limited (100 guesses/hour) | longer than the age of the universe |
| Average time to crack — online attack, no rate limit (1,000/second) | longer than the age of the universe |
| Average time to crack — stolen hashes, slow hash e.g. bcrypt (100,000/second) | longer than the age of the universe |
| Average time to crack — stolen hashes, fast hash e.g. MD5 on GPUs (100 billion/second) | 85.6 thousand years |
Open this example in the calculator
Time to crack a random password (all character types)
| Length | Entropy | bcrypt (100k/s) | Fast hash (100bn/s) |
|---|---|---|---|
| 8 characters | 53 bits | 1.1 thousand years | 9h 12m 51s |
| 10 characters | 66 bits | 9.5 million years | 9 years |
| 12 characters | 79 bits | longer than the age of the universe | 85.6 thousand years |
| 14 characters | 92 bits | longer than the age of the universe | 772.7 million years |
| 16 characters | 105 bits | longer than the age of the universe | longer than the age of the universe |
| 20 characters | 131 bits | longer than the age of the universe | longer than the age of the universe |
What makes a password strong
- Length matters most: each extra character multiplies the work for an attacker.
- Randomness: generated by a password manager, not chosen by a person.
- Unique for every site, so one leak does not expose other accounts.
- Protected by multi-factor authentication, which stops most account takeovers even if the password leaks.
Advice for businesses
- Store passwords with a slow, salted hash (Argon2id or bcrypt), never plain text or MD5/SHA-1.
- Rate-limit logins and lock or slow down repeated failures.
- Check new passwords against lists of breached passwords.
- Allow long passwords and paste, and do not force frequent changes without reason (NIST SP 800-63B).
- Require MFA for admin and remote access.
Open this calculator with your numbers
Every option can be set in the web address, so you can bookmark a scenario or send it to a colleague. AI assistants such as ChatGPT, Gemini, Claude and Perplexity can use the same parameters to open this calculator with your numbers and the result already on the page.
| Parameter | What it sets | Accepted values |
|---|---|---|
mode |
Password type | one of characters, passphrase |
length |
Length (characters) | number from 1 to 128, default 12 |
sets |
Character types used | comma-separated list of lower, upper, digits, symbols |
words |
Words in passphrase | number from 1 to 20, default 5 |
attack |
Attack scenario | one of online, online_fast, offline_slow, offline_fast |
Also available as plain text for AI assistants and a free JSON API (OpenAPI spec).
Last reviewed by the Infikey Technologies team.
Disclaimer
This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.