Skip to main content

Password Entropy - How to Measure Real Strength

About 2 min read

Entropy is a measure of uncertainty in information theory, and in the context of passwords it is an indicator that expresses how hard a password is to predict, measured in bits. The higher the entropy value, the harder the password is to guess. The entropy of a password is calculated from the number of character types and the password length used, allowing you to quantitatively evaluate its resistance to brute-force attacks.

Calculation Method and Concrete Numerical Examples

The entropy of a password is calculated as "log2(number of character types) x length." The following shows the entropy of representative configurations.

  • Lowercase letters only (26 types) x 8 characters = about 37.6 bits
  • Upper- and lowercase letters + digits (62 types) x 10 characters = about 59.5 bits
  • Upper- and lowercase letters + digits + symbols (95 types) x 12 characters = about 78.8 bits
  • Upper- and lowercase letters + digits + symbols (95 types) x 16 characters = about 105 bits
  • Upper- and lowercase letters + digits + symbols (95 types) x 20 characters = about 131 bits

Some strength meters found in password tools use this way of thinking about entropy as a rough guide (others estimate the number of guesses through pattern matching, so the calculation method differs from tool to tool). Every additional 10 bits multiplies the number of combinations that must be searched exhaustively by roughly 1,024. Increasing either the length or the number of character types raises entropy: with a 95-character set, each additional character adds about 6.6 bits, while widening the set from 62 to 95 types adds about 0.6 bits per character. However, the number of usable character types has an upper bound (roughly 95 printable ASCII characters), whereas the length has no inherent limit, so length is the side with more room to grow.

Where Entropy Fits in Policy Design

Organizational password policies sometimes set a minimum length and then reject strings found in dictionaries or in lists of previously breached passwords. NIST SP 800-63B states that estimating the entropy of user-chosen passwords is difficult, and presents an approach based primarily on password length instead. The document requires memorized secrets (passwords) to be at least 8 characters long while declining to impose additional complexity requirements such as mixing character types, and it calls for user-chosen passwords to be compared against a blocklist that includes previous breach corpuses and dictionary words.

Practical Application and Pitfalls

Entropy is a theoretical indicator of password strength, but there are points to watch out for in practice. The entropy calculation assumes "completely random generation," and passwords devised by humans are weak against dictionary attacks and pattern analysis, so their practical strength is lower than the calculated entropy. For example, "P@ssw0rd123!" has a rich variety of character types and appears to have high calculated entropy, but because it is a well-known pattern, it is broken instantly by a dictionary attack. Also, the time required for an exhaustive search is not fixed even for the same number of bits. It varies by orders of magnitude depending on the computing resources an attacker can marshal and on the hash function and iteration count (stretching) the service uses, so the time required cannot be pinned down from the bit count alone. By using a cryptographically secure random number generator, you can generate truly random passwords whose calculated entropy matches their practical strength.

Related Terms

Was this article helpful?