# Password strength calculator: entropy and time to crack

> Password strength is measured in bits of entropy: length × log2(size of the character set) for a random password, or words × log2(wordlist size) for a random passphrase. Each extra bit doubles the guesses needed. A random 12-character password using all four character types has about 79 bits; a 5-word Diceware passphrase about 65 bits. Human-chosen passwords are far weaker than these figures because attackers try common patterns first.

- Interactive version: https://infikeytechnologies.com/tools/password-strength-calculator
- Type: free instant calculator
- Category: Security & compliance
- Last reviewed: 2026-10-05
- Publisher: Infikey Technologies (https://infikeytechnologies.com)

## Example result (default inputs)

| Input | Value |
| --- | --- |
| Password type | Random characters |
| Length (characters) | 12 |
| Character types used | Lowercase (a–z), Uppercase (A–Z), Digits (0–9), Symbols (!@#…) |
| Words in passphrase | 5 |
| Attack scenario | Stolen hashes, slow hash e.g. bcrypt (100,000/second) |

**Average time to crack: longer than the age of the universe.** A random 12-character password from 95 characters has 78.8 bits of entropy. Average time to crack: longer than the age of the universe — stolen hashes, slow hash e.g. bcrypt (100,000/second).

Strong: good for important accounts, provided it is randomly generated and unique.

| Metric | Value |
| --- | --- |
| Entropy | 78.8 bits |
| Character set size | 95 characters |
| Possible combinations | ≈ 10^23.7 |
| Average time to crack — online attack, rate-limited (100 guesses/hour) | longer than the age of the universe |
| Average time to crack — online attack, no rate limit (1,000/second) | longer than the age of the universe |
| Average time to crack — stolen hashes, slow hash e.g. bcrypt (100,000/second) | longer than the age of the universe |
| Average time to crack — stolen hashes, fast hash e.g. MD5 on GPUs (100 billion/second) | 85.6 thousand years |

### Time to crack by attack type (log scale)

| Item | Value | Detail |
| --- | --- | --- |
| Online attack, rate-limited (100 guesses/hour) | longer than the age of the universe |  |
| Online attack, no rate limit (1,000/second) | longer than the age of the universe |  |
| Stolen hashes, slow hash e.g. bcrypt (100,000/second) (selected) | longer than the age of the universe |  |
| Stolen hashes, fast hash e.g. MD5 on GPUs (100 billion/second) | 85.6 thousand years |  |

- This tool never asks for your password: it calculates from length and character types only.
- Figures assume the password is generated randomly. Names, dictionary words, dates, keyboard patterns and reused or leaked passwords are cracked far faster.

Open this result on the website: https://infikeytechnologies.com/tools/password-strength-calculator?mode=characters&length=12&sets=lower%2Cupper%2Cdigits%2Csymbols&words=5&attack=offline_slow

## Use from a link or API

Add these query parameters to https://infikeytechnologies.com/tools/password-strength-calculator (pre-filled page), https://infikeytechnologies.com/tools/password-strength-calculator.md (this plain-text page) or https://infikeytechnologies.com/api/tools/password-strength-calculator (JSON).

| Parameter | Meaning | Accepted values |
| --- | --- | --- |
| `mode` | Password type | one of characters, passphrase |
| `length` | Length (characters) | number from 1 to 128, default 12 |
| `sets` | Character types used | comma-separated list of lower, upper, digits, symbols |
| `words` | Words in passphrase | number from 1 to 20, default 5 |
| `attack` | Attack scenario | one of online, online_fast, offline_slow, offline_fast |

- 8 characters, lowercase only: https://infikeytechnologies.com/tools/password-strength-calculator?mode=characters&length=8&sets=lower&words=5&attack=offline_slow
- 12 characters, all types: https://infikeytechnologies.com/tools/password-strength-calculator?mode=characters&length=12&sets=lower%2Cupper%2Cdigits%2Csymbols&words=5&attack=offline_slow
- 16 characters, all types: https://infikeytechnologies.com/tools/password-strength-calculator?mode=characters&length=16&sets=lower%2Cupper%2Cdigits%2Csymbols&words=5&attack=offline_slow
- 6-word passphrase: https://infikeytechnologies.com/tools/password-strength-calculator?mode=passphrase&length=12&sets=lower%2Cupper%2Cdigits%2Csymbols&words=6&attack=offline_slow

## How it is calculated

- **Random characters**: entropy = length × log₂(character set size)
- **Random passphrase**: entropy = words × log₂(7,776)
- **Average time to crack**: 2^entropy ÷ 2 ÷ guesses per second
- **Character set sizes**: lowercase 26, uppercase 26, digits 10, symbols 33

## Time to crack a random password (all character types)

| Length | Entropy | bcrypt (100k/s) | Fast hash (100bn/s) |
| --- | --- | --- | --- |
| 8 characters | 53 bits | 1.1 thousand years | 9h 12m 51s |
| 10 characters | 66 bits | 9.5 million years | 9 years |
| 12 characters | 79 bits | longer than the age of the universe | 85.6 thousand years |
| 14 characters | 92 bits | longer than the age of the universe | 772.7 million years |
| 16 characters | 105 bits | longer than the age of the universe | longer than the age of the universe |
| 20 characters | 131 bits | longer than the age of the universe | longer than the age of the universe |

## What makes a password strong

- Length matters most: each extra character multiplies the work for an attacker.
- Randomness: generated by a password manager, not chosen by a person.
- Unique for every site, so one leak does not expose other accounts.
- Protected by multi-factor authentication, which stops most account takeovers even if the password leaks.

## Advice for businesses

- Store passwords with a slow, salted hash (Argon2id or bcrypt), never plain text or MD5/SHA-1.
- Rate-limit logins and lock or slow down repeated failures.
- Check new passwords against lists of breached passwords.
- Allow long passwords and paste, and do not force frequent changes without reason (NIST SP 800-63B).
- Require MFA for admin and remote access.

## FAQ

### How long does it take to crack a 12-character password?

A random 12-character password using all character types has about 79 bits of entropy: practically uncrackable against bcrypt-protected hashes, and tens of thousands of years at 100 billion guesses a second. Human-chosen 12-character passwords can fall in hours or days.

### What is password entropy?

A measure of how unpredictable a password is, in bits. Each extra bit doubles the number of guesses needed to find it.

### Are passphrases better than passwords?

Random passphrases are easier to remember for the same strength. Six random words give about 78 bits — similar to a random 12-character password.

### Is it safe to type my password into an online strength checker?

It is best not to. This calculator only asks for the length and character types, so your password never leaves your head.

### How many bits of entropy is a strong password?

Aim for at least 75–80 bits for important accounts, and more for master passwords and encryption keys.

## Get expert help

Send these results to an Infikey Technologies specialist from the form on https://infikeytechnologies.com/tools/password-strength-calculator#estimate or via https://infikeytechnologies.com/contact.

More free calculators: https://infikeytechnologies.com/tools.md

## Disclaimer

This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.
