Free tools / Password strength
Password strength tester
An entropy estimate and the time a fast offline attack would need. The password never leaves this page.
- 12 or more characters
- Lowercase letter
- Uppercase letter
- Number
- Symbol
- No common word or run
Entropy is a count of how many guesses a password could take, expressed in bits: each extra bit doubles the work. It comes from the length and the size of the character set, minus a penalty for the things attackers try first: dictionary words, keyboard runs, repeated characters and years. The crack time assumes an attacker with the hashed password and fast hardware, not someone typing at a login form.
Length beats cleverness. Four unrelated words are stronger than a short word with a number and a symbol bolted on, and far easier to remember. Better still, let a password manager generate and keep them, and spend your memory on the one that unlocks it.