Password Entropy
Calculator
Results
- Entropy (bits)
- 78.655066
- Bits per character
- 6.554588
- Total combinations
- 4.7592031481425336e+23
Computing results
| Entropy (bits) | 78.655066 |
| Bits per character | 6.554588 |
| Total combinations | 4.7592031481425336e+23 |
formula-map diagram
- Entropy (bits)
- 78.655066
- Bits per character
- 6.554588
- Total combinations
- 4.7592031481425336e+23
Computing relationship
Formula
H = length × log2(charset_size)= 78.655066220132
Note
This is a simplified model: it applies the standard computing formula to the numbers you entered and ignores protocol overhead, compression variability, retries, contention and other real-world effects. Size your systems with measured data.
More in Technology and computing
See all →Frequently asked questions
What does password entropy actually measure?+
Entropy, measured in bits, quantifies how unpredictable a password is based on the size of the character set used (lowercase, uppercase, numbers, symbols) and the password's length. Higher entropy means more possible combinations an attacker would have to try, making the password harder to guess or brute-force.
Why does adding a few more characters matter more than adding symbol complexity?+
Entropy grows exponentially with length but only linearly-ish with character set size, so a longer password using a smaller character set can have more entropy than a shorter, more complex-looking one. This is why security guidance has shifted toward encouraging longer passphrases over short, symbol-heavy passwords.
Does this calculator account for common password patterns?+
No, standard entropy calculations assume the password is chosen uniformly at random from the given character set. Real passwords using dictionary words, keyboard patterns, or predictable substitutions (like '@' for 'a') have far less effective entropy than the raw calculation suggests, because attackers check these patterns first.
How much entropy is considered secure?+
As a general guideline, 60+ bits is reasonable for most personal accounts, while 80+ bits is recommended for high-value or sensitive accounts, though the right threshold also depends on how the service stores and protects passwords against attack.
Is a randomly generated password always better than a memorable passphrase?+
For the same entropy value, they offer equivalent theoretical security, but a truly random password is harder to memorize, which often leads to unsafe practices like reuse or writing it down. A sufficiently long random passphrase of unrelated words can offer comparable entropy while remaining memorable.