Security · Utilities

Password entropy: why length beats complexity

Published 2026-10-05

Entropy is the measure of how unpredictable a password is, expressed in bits. Each bit doubles the number of guesses an attacker needs to try. A password with 64 bits of entropy takes 2^64 = 18 quintillion guesses to crack by brute force. A password with 30 bits takes 2^30 = 1 billion guesses — crackable in hours on a modern GPU rig.

TL;DR

A 16-character password made of lowercase letters is stronger than an 8-character password with mixed case, numbers, and symbols. Here is the math.

How entropy is calculated

Entropy = log2(charset_size^length). For a password of length L using characters from a charset of size N, the entropy in bits is L × log2(N). For lowercase letters (charset size 26), each character adds log2(26) = 4.7 bits. For all printable ASCII (charset size ~95), each character adds log2(95) = 6.6 bits. For a random 16-character lowercase-only password: 16 × 4.7 = 75 bits. For an 8-character mixed-case-symbols password: 8 × 6.6 = 53 bits.

Why length wins

Doubling the length doubles the entropy. Doubling the charset size adds log2(2) = 1 bit per character. So adding two random characters is roughly equivalent to adding one full character class. A 16-character lowercase password (75 bits) is much stronger than an 8-character symbol-laden password (53 bits), and far easier to remember.

How password generators measure entropy

A cryptographically secure password generator uses crypto.getRandomValues or /dev/urandom. Each character is drawn independently from the charset, with no relationship between characters. The entropy is then L × log2(N). A non-secure generator (using Math.random, time-based seeds, or pattern-based generation) produces lower entropy even at the same length.

What the entropy meter tells you

The /password/ tool shows an entropy meter in real time. Below 40 bits is weak (crackable in seconds). 40–60 bits is moderate (crackable in hours to days). 60–80 bits is strong (crackable in years to decades). 80+ bits is essentially uncrackable by brute force. A reasonable target is 64+ bits for personal accounts, 80+ for high-value accounts.

Try it →

Run the Password generator tool on sitetrace.it.com — paste a value and get an instant answer.

Open Password generator