Security & compliance · Free tool

Password strength calculator: entropy and time to crack

Password strength is measured in bits of entropy: length × log2(size of the character set) for a random password, or words × log2(wordlist size) for a random passphrase. Each extra bit doubles the guesses needed. A random 12-character password using all four character types has about 79 bits; a 5-word Diceware passphrase about 65 bits. Human-chosen passwords are far weaker than these figures because attackers try common patterns first.

Free, no sign-up · By Infikey Technologies · Updated

Use the calculator

Your numbers

Reset
Password type

Used for random characters. Enter the length only — never your actual password.

Character types used

Used for passphrases chosen at random from a 7,776-word list.

Result

Average time to crack

longer than the age of the universe

A random 12-character password from 95 characters has 78.8 bits of entropy. Average time to crack: longer than the age of the universe — stolen hashes, slow hash e.g. bcrypt (100,000/second).

Strong: good for important accounts, provided it is randomly generated and unique.

Time to crack by attack type (log scale)
  • Online attack, rate-limited (100 guesses/hour) longer than the age of the universe
  • Online attack, no rate limit (1,000/second) longer than the age of the universe
  • Stolen hashes, slow hash e.g. bcrypt (100,000/second) longer than the age of the universe
  • Stolen hashes, fast hash e.g. MD5 on GPUs (100 billion/second) 85.6 thousand years
Password strength & entropy calculator results
Entropy 78.8 bits
Character set size 95 characters
Possible combinations ≈ 10^23.7
Average time to crack — online attack, rate-limited (100 guesses/hour) longer than the age of the universe
Average time to crack — online attack, no rate limit (1,000/second) longer than the age of the universe
Average time to crack — stolen hashes, slow hash e.g. bcrypt (100,000/second) longer than the age of the universe
Average time to crack — stolen hashes, fast hash e.g. MD5 on GPUs (100 billion/second) 85.6 thousand years
  • This tool never asks for your password: it calculates from length and character types only.
  • Figures assume the password is generated randomly. Names, dictionary words, dates, keyboard patterns and reused or leaked passwords are cracked far faster.

Estimates for planning only, not professional advice. Infikey Technologies accepts no liability for decisions based on these results — read the disclaimer.

Want an expert to sanity-check these numbers?

Send these results to an Infikey specialist and get a reply for your situation.

Ask an expert

How this calculator works

MetricFormula
Random charactersentropy = length × log₂(character set size)
Random passphraseentropy = words × log₂(7,776)
Average time to crack2^entropy ÷ 2 ÷ guesses per second
Character set sizeslowercase 26, uppercase 26, digits 10, symbols 33

Worked example

With these inputs:

  • Password type: Random characters
  • Length (characters): 12
  • Character types used: Lowercase (a–z), Uppercase (A–Z), Digits (0–9), Symbols (!@#…)
  • Words in passphrase: 5
  • Attack scenario: Stolen hashes, slow hash e.g. bcrypt (100,000/second)

Average time to crack: longer than the age of the universe. A random 12-character password from 95 characters has 78.8 bits of entropy. Average time to crack: longer than the age of the universe — stolen hashes, slow hash e.g. bcrypt (100,000/second).

Entropy78.8 bits
Character set size95 characters
Possible combinations≈ 10^23.7
Average time to crack — online attack, rate-limited (100 guesses/hour)longer than the age of the universe
Average time to crack — online attack, no rate limit (1,000/second)longer than the age of the universe
Average time to crack — stolen hashes, slow hash e.g. bcrypt (100,000/second)longer than the age of the universe
Average time to crack — stolen hashes, fast hash e.g. MD5 on GPUs (100 billion/second)85.6 thousand years

Open this example in the calculator

Time to crack a random password (all character types)

LengthEntropybcrypt (100k/s)Fast hash (100bn/s)
8 characters 53 bits 1.1 thousand years 9h 12m 51s
10 characters 66 bits 9.5 million years 9 years
12 characters 79 bits longer than the age of the universe 85.6 thousand years
14 characters 92 bits longer than the age of the universe 772.7 million years
16 characters 105 bits longer than the age of the universe longer than the age of the universe
20 characters 131 bits longer than the age of the universe longer than the age of the universe

What makes a password strong

  • Length matters most: each extra character multiplies the work for an attacker.
  • Randomness: generated by a password manager, not chosen by a person.
  • Unique for every site, so one leak does not expose other accounts.
  • Protected by multi-factor authentication, which stops most account takeovers even if the password leaks.

Advice for businesses

  • Store passwords with a slow, salted hash (Argon2id or bcrypt), never plain text or MD5/SHA-1.
  • Rate-limit logins and lock or slow down repeated failures.
  • Check new passwords against lists of breached passwords.
  • Allow long passwords and paste, and do not force frequent changes without reason (NIST SP 800-63B).
  • Require MFA for admin and remote access.

Every option can be set in the web address, so you can bookmark a scenario or send it to a colleague. AI assistants such as ChatGPT, Gemini, Claude and Perplexity can use the same parameters to open this calculator with your numbers and the result already on the page.

ParameterWhat it setsAccepted values
mode Password type one of characters, passphrase
length Length (characters) number from 1 to 128, default 12
sets Character types used comma-separated list of lower, upper, digits, symbols
words Words in passphrase number from 1 to 20, default 5
attack Attack scenario one of online, online_fast, offline_slow, offline_fast

Example: https://infikeytechnologies.com/tools/password-strength-calculator?mode=characters&length=8&sets=lower&words=5&attack=offline_slow

Also available as plain text for AI assistants and a free JSON API (OpenAPI spec).

Last reviewed by the Infikey Technologies team.

Disclaimer

This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.

FAQ

Password strength & entropy calculator questions

How long does it take to crack a 12-character password? +

A random 12-character password using all character types has about 79 bits of entropy: practically uncrackable against bcrypt-protected hashes, and tens of thousands of years at 100 billion guesses a second. Human-chosen 12-character passwords can fall in hours or days.

What is password entropy? +

A measure of how unpredictable a password is, in bits. Each extra bit doubles the number of guesses needed to find it.

Are passphrases better than passwords? +

Random passphrases are easier to remember for the same strength. Six random words give about 78 bits — similar to a random 12-character password.

Is it safe to type my password into an online strength checker? +

It is best not to. This calculator only asks for the length and character types, so your password never leaves your head.

How many bits of entropy is a strong password? +

Aim for at least 75–80 bits for important accounts, and more for master passwords and encryption keys.

Talk to an expert

Want an expert to sanity-check these numbers?

Your inputs and results are attached automatically, so we can reply with specific advice on Cybersecurity.