Skip to content
VaultPass

Fundamentals

What password entropy is, and why it decides whether yours holds

The VaultPass desk5 min read
A blackboard covered in chalked mathematics

When a website tells you your password is strong, it is almost always counting capitals and symbols. The measure actually used by the people who break passwords for a living is a different one. It is called entropy, and it explains why four random words beat a string of odd characters.

There is a question that sounds simple and is not: how strong is this password?

Website strength meters usually answer by looking at appearance: does it have capitals? digits? symbols? By that standard, Passw0rd! comes out green and correct horse battery staple comes out amber. Both verdicts are backwards.

The correct measure is called entropy, and it does not look at the result. It looks at how the result was chosen.

The idea, without formulas

Entropy counts how many possibilities your password had of being something else. It is expressed in bits, and each bit doubles the attacker’s work:

  • 10 bits ≈ 1,000 possibilities
  • 20 bits ≈ 1,000,000
  • 40 bits ≈ 1 trillion
  • 60 bits ≈ 1 quintillion

Because it doubles with every bit, the difference between 50 and 60 bits is not “a bit more”: it is a thousand times more.

The important part is that entropy is computed over the procedure, not over the string. If you roll a six-sided die, the result carries 2.6 bits of entropy whatever comes up. If you write “4” because you felt like it, the entropy is essentially zero — even though the character is identical.

This is what almost every meter skips, and it is why passwords that “look random” fail.

Why Passw0rd! is worth nothing

On paper it has nine characters, a capital, a digit and a symbol. A naive meter computes: 9 characters × a 94-symbol alphabet ≈ 59 bits. Sounds fine.

But an attacker does not try combinations at random. They try from most likely to least likely:

  1. The most-used passwords in the world.
  2. Dictionary words.
  3. Words with the usual substitutions: a→4, o→0, e→3.
  4. With a capital at the start.
  5. With a digit or symbol at the end.

Passw0rd! sits at the intersection of every one of those rules. Its real entropy is a handful of bits: it is among the first things tried. Cracking tools have been folding in these rules for decades.

By contrast, twelve genuinely machine-random characters — k7$Rm2xQp!9v — do carry the bits they appear to, because there is no pattern to get ahead of.

Where the bits come from in each method

Random characters. Each character contributes about 6.55 bits if the alphabet is 94 symbols (letters, digits and punctuation). A convenient approximation:

Length Approximate entropy Verdict
8 characters 52 bits Not enough today
12 characters 79 bits Solid
16 characters 105 bits More than enough for anything
20 characters 131 bits Master password

Random words. With the classic Diceware list of 7,776 words, each randomly chosen word contributes 12.9 bits:

Words Entropy Verdict
4 words 51 bits Short for anything important
5 words 64 bits Good for general use
6 words 77 bits Solid, suitable as a master password
7 words 90 bits Maximum peace of mind

A detail that surprises people: the attacker can know you used Diceware and which list, and the arithmetic does not change. The security is in the randomness of the choice, not in hiding the method. This is Kerckhoffs’s principle, and it is why a well-built system does not depend on keeping secrets about how it works.

You can generate one in the passphrase tool, which uses the browser’s cryptographic randomness source.

How many bits you actually need

It depends what you are defending against.

Against an online attack, where the attacker tries the website’s form, the service rate-limits attempts. At 40 bits it is already unfeasible. In practice, what kills you here is not entropy — it is having reused the password.

Against an offline attack, where the database is stolen and cracked on the attacker’s own hardware, the speed depends on how the service stored the passwords:

  • With a modern, slow algorithm (bcrypt, scrypt, Argon2), thousands of attempts per second. 65 bits is plenty.
  • With something old and fast (MD5, unsalted SHA-1), billions per second. Here you want 80 bits or more.

The problem is that you do not know which one they used. So the practical recommendation is simple: aim for 70–80 bits on anything that matters. That is 12–13 random characters, or 6 words.

The three mistakes that destroy entropy

Choosing the words yourself. If you pick five words “at random” by thinking about it, they do not come out random: they come out related and drawn from a vocabulary of a few hundred common terms. Real entropy drops by more than half.

Reusing the structure. Amazon2024!, Netflix2024!, Gmail2024!. If the attacker sees one, they deduce the rest. The entropy of the second password, for someone who knows the first, is close to zero.

Using personal data. Children’s names, pets, dates, football teams. All of it is on your social media and it is the first thing tried in a targeted attack.

How to check yours

The VaultPass strength checker estimates strength by combining length, character classes, keyboard patterns and common words, and does the calculation in your browser without sending the password.

Two honest warnings about any meter, this one included:

  • It can overestimate if your password contains a personal pattern the tool does not know about.
  • It does not know whether it is unique. A password with 100 bits of entropy that has already leaked elsewhere is worth zero. So run it through the breach checker as well.

Entropy measures how hard your password is to guess. It does not measure how easy it is to obtain by another route.

In short

  • Entropy measures how the password was chosen, not what it looks like.
  • Each bit doubles the attacker’s work.
  • Twelve random characters or five random words is a good target; six words for a master key.
  • Choosing “at random” yourself destroys entropy: let a machine generate it.
  • All the entropy in the world is worthless if the password is reused or leaked.

Frequently asked

The questions that keep coming up

What is password entropy?

It is a measure, in bits, of how many possibilities an attacker would have to try to land on it. Each additional bit doubles that work, so 60 bits is twice as hard as 59.

How many bits of entropy does a password need?

As a guide: below 50 bits is weak, 60 to 70 works for ordinary accounts on well-built services, and from 80 upwards is considered solid for critical accounts and master passwords.

Why does a phrase of words have more entropy than a password with symbols?

Because entropy depends on how many options existed at each choice, not on how strange the result looks. Choosing at random from 7,776 words contributes about 12.9 bits per word, so five words beat most twelve-character passwords.

My password looks random but I chose it myself. Does that count as random?

No. Entropy measures the selection process, not the appearance of the result. A key chosen by a person follows unconscious patterns and its real entropy is far lower than it looks.

Keep reading