What makes a password strong
A password is strong when it's hard to guess, and that comes down to one thing: how many possibilities an attacker would have to try before landing on it. Apparent complexity — a capital letter, a number at the end, an @ in place of an a — only helps if it actually multiplies those possibilities, and in passwords people pick themselves, it almost never does. This guide explains how to measure strength with entropy, how much of it you need in practice, and why the way a password is generated matters as much as its length.
Entropy: measuring strength in bits
Entropy measures how many different passwords a generation method could have produced, expressed in bits. Every bit doubles the number of possibilities: a 40-bit password comes from a pool of 2⁴⁰ (roughly a trillion) candidates; a 41-bit password, from twice that.
For a randomly generated password, where each character is picked independently from a set of N symbols, the formula is straightforward:
entropy = L × log₂(N)
where L is the length. For example, 12 characters picked at random from lowercase, uppercase, digits, and 25 symbols (N = 87) give 12 × log₂(87) ≈ 12 × 6.44 ≈ 77.3 bits. At 16 characters, the same math gives 103 bits.
The table below shows how many bits each character contributes for a given set, and how long a password needs to be to reach 60 and 80 bits:
| Character set | Symbols (N) | Bits per character | Length for 60 bits | Length for 80 bits |
|---|---|---|---|---|
| Digits only | 10 | 3.32 | 19 | 25 |
| Lowercase | 26 | 4.70 | 13 | 18 |
| Upper and lowercase | 52 | 5.70 | 11 | 15 |
| Letters and digits | 62 | 5.95 | 11 | 14 |
| Letters, digits, and symbols | 87 | 6.44 | 10 | 13 |
| Words from a Diceware list | 7,776 | 12.92 per word | 5 words | 7 words |
Two things jump out. First, length beats variety. Going from letters and digits (62) to adding symbols (87) saves you about one character on the way to 80 bits, while each extra character adds 5 to 6.5 bits. Second, a short phrase of randomly chosen words holds its own against a string of symbols that's far harder to remember.
How many bits is enough
Entropy gets concrete once you translate it into time. Take a common worst case: an attacker has the database of password hashes and tries candidates offline at 10 billion per second — a realistic rate for a multi-GPU rig attacking a fast hash. On average, they find the password after searching half the space:
| Entropy | Average time to guess |
|---|---|
| 40 bits | under a minute |
| 50 bits | about 16 hours |
| 60 bits | almost 2 years |
| 72 bits | about 7,500 years |
| 80 bits | about 1.9 million years |
| 100 bits | trillions of years |
Against an online service that rate-limits login attempts, 40 bits may be plenty. But a password has no say in where its hash ends up, and database breaches are common. That's why the practical baseline is at least 80 bits for any account that matters, and 100 or more for master passwords or keys that protect other keys. If the service stores passwords with a slow, salted hash (bcrypt, scrypt, or Argon2), the attacker gets through orders of magnitude fewer guesses per second — but that's up to the service, not to whoever picks the password.
Why the formula fails for made-up passwords
The L × log₂(N) formula assumes every character was picked at random. People don't pick at random: they start with a capital, end with a number or a year, swap a for @ and o for 0, and build on real words. Modern cracking tools (hashcat, John the Ripper) try exactly those patterns first, using dictionaries of billions of leaked passwords plus mangling rules.
Summer2024! is 11 characters with upper, lower, digits, and a symbol. By the formula, that's 71 bits. In practice it's a common word, a recent year, and the most popular symbol tacked on the end — it falls within the first few minutes of any rules-based attack. A password's real entropy lives in the process that generated it, not in the characters it happens to contain.
Passphrases
When a password has to be memorized — your password manager's, your computer login, your disk encryption key — a random passphrase is the best option. The Diceware method uses a list of 7,776 words (6⁵, one for every combination of five dice) and picks each word by rolling dice or using a cryptographic generator. Each word adds log₂(7776) ≈ 12.9 bits:
- 4 words ≈ 52 bits: not enough to hold up against an offline attack.
- 6 words ≈ 78 bits: a solid minimum for most uses.
- 7 words ≈ 90 bits: comfortable even for a master password.
The catch is the same as with characters: the words have to come from a random draw, not a choice. A famous quote, a song lyric, or "correct horse battery staple" lifted straight from the well-known comic all have near-zero entropy, because they're already in the attack dictionaries.
Generating truly at random
Everything above depends on the generator being unpredictable. In JavaScript, Math.random() won't do: it's built for simulations and games, not security, and in several engines its internal state can be reconstructed from a handful of outputs. Passwords need a cryptographically secure generator (CSPRNG) — in the browser that's crypto.getRandomValues() from the Web Crypto API, and at the OS level it's /dev/urandom or its equivalent.
Toolbit's password generator uses crypto.getRandomValues(), calculates entropy with the same formula as this guide, and shows it next to the password, so you can adjust the length until you hit the level you want. The password is generated in your browser and never sent to a server.
What current guidelines say
NIST's digital identity guidelines (SP 800-63B), which many organizations use as their reference, overturned several rules that were considered best practice for years:
- Don't impose composition rules ("at least one uppercase letter, one number, and one symbol"). They push people toward the predictable patterns described above without adding real entropy.
- Don't force periodic changes. Mandatory rotation produces passwords like
Summer2024!→Fall2024!. Change a password only when there's evidence it was compromised. - Check against lists of breached passwords and reject any that appear.
- Allow long passwords (at least 64 characters) and any characters, spaces included, so passphrases are practical. The 2025 revision also raised the minimum to 15 characters for passwords used without a second factor.
Practical checklist
- A different password for every service. Reuse is the most common way accounts get compromised: when one site leaks, attackers try the same credentials everywhere else.
- A password manager to store them. That way each one can be a random 16- or 20-character string you never need to remember.
- A 6- or 7-word passphrase for the password manager's master password — the only one you actually have to memorize.
- Two-factor authentication wherever it's offered, ideally with an authenticator app or a hardware key rather than SMS.
- 80 bits as the floor for generated passwords. With letters, digits, and symbols, that's 13 characters; 16 gives you plenty of margin.
Summary
Password strength is measured in bits of entropy, and entropy can only be calculated when the password was generated at random. Length matters more than character variety, randomly drawn word phrases are the best choice for anything you need to remember, and a cryptographic generator plus a password manager takes care of the rest.