Password Entropy Explained (and How to Calculate It)
The worst argument in password security is the one about which characters you must include. An uppercase letter here, a symbol there, and you have a password like P@ssw0rd! that is hard to type, easy to forget, and weak anyway. Password entropy is the concept that settles the argument: it measures, in bits, how many guesses an attacker would need to try on average before hitting your password. The number is not decoration. It is the whole story of password strength.
Entropy is what separates a password you can defend from a password you cannot. This guide explains what bits of entropy mean, why length beats complexity every time, and how to calculate entropy by hand or with a tool. Once you can think in bits, you will stop worrying about character rules and start worrying about the only metric that matters.
What are bits of entropy?
A bit of entropy is a yes/no question that splits the search space in half. A coin flip has one bit of entropy. A fair roll of a six-sided die has about 2.6 bits, because log₂(6) is roughly 2.6. Every bit doubles the number of possible passwords, so each bit also doubles the work an attacker must do to brute-force the password.
The formula is simple:
entropy (bits) = log₂(possible passwords) = length × log₂(character set size)
A password of length 8 drawn from a 94-character printable set has 8 × log₂(94), which is about 52 bits. A password of length 16 from the same set is 16 × log₂(94), about 105 bits. The length term is multiplied, so it dominates. That is the mathematical reason length beats complexity: doubling the length doubles the exponent, while adding characters only grows the base.
Why length beats complexity
Consider two passwords. The first is Tr0ub4dor&3, thirteen characters from a large set. The second is correcthorsebatterystaple, twenty-five lowercase letters. The first looks stronger to most people because it is decorated with complexity. It is not.
The first password is eleven to twelve bits worse than it looks because it is a recognizable word with predictable substitutions, and its entropy is lower than a random string of the same length. The passphrase, by contrast, is four common words, and even if you model it conservatively as four random words from a 10,000-word list, it carries 4 × log₂(10,000) or about 53 bits of entropy. In practice the passphrase is dramatically harder to guess, easier to remember, and far easier to type on a phone.
Complexity rules are a brute-force patch on short passwords. Length solves the problem directly, because every added character multiplies the guess space. A sixteen-character lowercase-only password (16 × log₂(26), about 75 bits) beats an eight-character maximum-complexity password (about 52 bits) by a comfortable margin, and it is easier to remember.
How to calculate entropy by hand
You can compute an honest estimate of entropy in three steps.
- Decide how the password was generated. Was it random? A random string’s entropy comes entirely from length and character set. Was it a passphrase of words? Estimate with the number of words times the size of the word list. Never count on “hacker-proof” substitutions adding real bits; attackers model them.
- Count the character set. Lowercase is 26, add digits for 36, add uppercase for 62, add symbols for 94. For a passphrase, use your estimated dictionary size, typically 5,000 to 20,000.
- Multiply length by log₂ of the set size. A quick approximation: log₂(26) is about 4.7, log₂(94) is about 6.55, and log₂(10,000) is about 13.3. Multiply and you have the bit count.
A rough baseline is that a password should sit above 60 bits for low-value accounts, and above 80 bits for anything that protects money or credentials. Run the numbers for your own passwords in the free entropy calculator, which applies this formula directly and shows you where your passwords fall.
What good entropy does not protect you from
High entropy stops offline brute force, where an attacker has the hashed password dump and can try guesses at speed. It does nothing for the attack paths that ignore guessing entirely:
- Phishing. A random 20-character password is worthless if you type it into a fake login page.
- Password reuse. The strongest password on the planet fails the moment it is reused on a site that leaks it.
- Credential stuffing. Same story: breached credentials from one site are replayed everywhere.
- Keyloggers and malware. If the machine is compromised, guessing strength is irrelevant.
This is why entropy is a floor, not a ceiling. Pair high-entropy passwords with a password manager, generate each one independently, and put a second factor on top. Entropy makes the offline attack expensive; the rest of your hygiene keeps the password out of the attacker’s hands in the first place.
Next steps
Check the passwords you currently rely on with the entropy calculator, and replace anything under 60 bits with a long random passphrase or a generated password. Then enable a second factor on the accounts that matter.
Try it now: open the entropy calculator tool — free, runs entirely in your browser, nothing is uploaded.