Entropy, Not "Complexity Rules"
Password strength is measured in bits of entropy: how many guesses an attacker needs on average. It depends on how the password was *generated*, not how it looks.
``
entropy = length × log₂(pool size)
`
| Password | Pool | Length | Entropy |
|---|---|---|---|
hunter2 | — | — | ~0 (in every wordlist) |
Tr0ub4dor&3 | 90 | 11 | ~28 real bits (predictable substitutions) |
x7Kq2mWvR9pLz4Tn | 62 | 16 | 95 bits |
correct-horse-battery-staple | 7776 words | 4 | 52 bits |
| 20 chars, all sets | 90 | 20 | 130 bits |
This is why "must contain an uppercase letter and a symbol" rules produce weak passwords:
they push people to Password1!, which is common enough to be in every cracking list.What the Crack Times Mean
The estimates here assume 10¹² guesses per second — an offline attack against a fast hash
like unsalted SHA-256 on rented GPUs. Against a properly stored password (bcrypt, scrypt,
Argon2) the real rate is thousands of guesses per second, so these figures are the
pessimistic bound.
| Entropy | Offline (10¹²/s) | Verdict |
|---|---|---|
| 40 bits | ~9 minutes | Broken |
| 60 bits | ~18 days | Weak |
| 80 bits | ~38,000 years | Reasonable |
| 100 bits | ~40 billion years | Strong |
| 128 bits | Heat death territory | Overkill, which is fine |
Passphrases
Four random words from a 7,776-word list give 51.7 bits — comparable to a 9-character
random string, and far easier to type on a TV remote or phone keyboard. The security comes
from the randomness of the *selection*, so choosing words yourself destroys it.
Practical Rules
Never reuse a password. Credential stuffing works because people do.- Length over character classes. 20 lowercase characters beats 8 mixed ones.
- Use a password manager. It removes the reuse temptation entirely.
- Turn on 2FA where it exists; a leaked password then is not enough on its own.
Length Beats Complexity
Every additional character multiplies the search space by the size of the alphabet. Every
additional character *class* adds a much smaller amount, once.
Setting Alphabet Bits per character Lowercase only 26 4.7 Alphanumeric 62 5.95 Alphanumeric + symbols 92 6.52
Adding symbols to an alphanumeric password buys about 0.6 bits per character. Adding two
characters of length buys about 12. This is why the composition rules that dominated
password policy for twenty years were a mistake: they made passwords harder for people and
barely harder for machines.Length (alphanumeric + symbols) Entropy Time at 10¹² guesses/sec 8 52 bits ~1 hour 12 78 bits ~5,000 years 16 104 bits astronomically long 20 130 bits astronomically long
Twelve is the modern floor. Sixteen is the sensible default. Beyond twenty, the password has
stopped being the weak point in any realistic attack.What NIST Actually Recommends Now
The 2017 revision of NIST SP 800-63B reversed most of the received wisdom, and it is worth
knowing because a lot of policy has not caught up:
No mandatory periodic rotation. Forced changes push people towardSummer2025!then
Summer2026!. Change on evidence of compromise, not on a calendar.
- No composition rules. Requiring one of each class produces predictable patterns —
capital first, digit and ! last.
- Check against known-breached lists. This is the control that actually works, because
credential stuffing beats brute force by an enormous margin.
- Allow long passwords and all characters, including spaces and Unicode.
- Allow paste. Blocking it defeats password managers, which are the single largest
improvement available to any user.Passphrases, and Why They Must Be Generated
A passphrase of randomly chosen words is easier to remember and, at a sensible word count,
stronger than the short password people actually pick.
Words 2,048-word list 7,776-word list (Diceware) 4 44 bits 52 bits 5 55 bits 65 bits 6 66 bits 77 bits
The entropy comes from the list size and the count, not from how the phrase looks. A phrase
*you* choose is not random — it comes from song lyrics, film titles and your own vocabulary,
all of which an attacker can model. "correct horse battery staple" is famous precisely
because it was generated.Use a passphrase where you must memorise it: a password manager's master password, disk
encryption, an SSH key. Everywhere else, let the manager store a long random string you will
never see.
Which Generator to Use
- [Strong password](/dev/strong-password-generator) — the general
default at 20 characters.
- [12](/dev/password-generator/random-password-generator-12-characters),
[16](/dev/password-generator/random-password-generator-16-characters),
[32](/dev/password-generator/random-password-generator-32-characters) or
[64 characters](/dev/password-generator/random-password-generator-64-characters) when a
specific length is required — 32 and above are machine credentials, not human ones.
- [Alphanumeric](/dev/password-generator/alphanumeric-password-generator) for systems
that break on punctuation, which is more of them than it should be.
- [WiFi](/dev/password-generator/wifi-password-generator) — long, no symbols, because it
gets typed on a television remote.
- [Passphrase](/dev/passphrase-generator) or
[memorable](/dev/password-generator/memorable-password-generator) for anything you have
to keep in your head.Generated in Your Browser, From the Right Source
Every value comes from crypto.getRandomValues(), the platform's cryptographically secure
random source — not Math.random()`, which is fast, predictable, and unfit for this. Nothing
is transmitted and nothing is stored. You can verify that by disconnecting from the network
and generating another.