Entropy Calculator
Analyze password cryptographic security using Shannon Information Entropy mathematics. Features detailed brute-force benchmarks across four attack scenarios. For quick password strength checks with recommendations, see our Password Entropy Calculator.
Brute-Force Attack Benchmarks (Est.)
| Attack Scenario | Speed Rate | Estimated Time to Crack |
|---|---|---|
| Standard Web App (throttled) | 100 guesses/sec | — |
| Desktop CPU (offline script) | 100,000 guesses/sec | — |
| GPU Brute Force (High-end) | 10,000,000 guesses/sec | — |
| GPU Cluster (Supercomputer) | 100,000,000,000 guesses/sec | — |
How entropy is calculated
This is an educational, technical tool for understanding entropy theory and comparing character set impacts. It provides detailed brute-force benchmarks across four attack scenarios (throttled web app through GPU cluster), making it ideal for learning how entropy works and evaluating password strategies.
Information entropy represents the complexity or unpredictability of a password. It is calculated using the formula:
Entropy (E) = L × log₂ (R)
Where L is the password character length, and R is the pool size of unique characters available. If a password contains only digits (0-9), R = 10. If it contains both digits and lowercase letters, R = 36. An entropy level above 60 bits is generally considered secure against standard offline attacks, while 80 bits or higher is highly resistant.
What Entropy Actually Measures
Entropy measures bits of randomness — specifically, how many possible combinations exist for a given password. Each bit of entropy represents a doubling of the search space an attacker must explore.
Where L is the password length and R is the character pool size. For example, a 10-character password drawn from 95 printable ASCII characters yields 10 × log₂(95) ≈ 65.7 bits of entropy.
Each additional bit of entropy doubles the number of possible combinations. A password with 60 bits has 2⁶⁰ ≈ 1.15 × 10¹⁸ combinations; adding just 10 more bits (to 70) increases that to 2⁷⁰ ≈ 1.18 × 10²¹ — roughly a thousand-fold increase.
80+ bits is strong for most real-world purposes. 128+ bits is considered extremely strong and computationally infeasible to brute-force with any foreseeable technology.
Entropy vs. Practical Strength
High entropy does not guarantee a good password. A random string like x7K!mP$9qR has high entropy, but it's impossible to remember and often leads users to reuse it — defeating the purpose entirely.
Passphrases solve this trade-off. A 5–6 word passphrase drawn from a large wordlist (like Diceware) can achieve 65–80 bits of entropy while remaining easy to memorize. The trade-off is length, not complexity.
Dictionary attacks significantly reduce effective entropy for predictable words. If an attacker knows you're using English words, the effective pool shrinks from thousands of characters to ~77,000 common English words — making the entropy calculation for random characters misleading for passphrases.
For real-world password analysis, the Password Strength Checker is more reliable because it accounts for patterns, dictionary words, and common substitutions — not just raw bit count.
Recommended Entropy Levels
Target entropy varies by use case. Use these thresholds when choosing passwords or keys:
| Use Case | Minimum | Recommended |
|---|---|---|
| Web account passwords | 60 bits | 80+ bits |
| Master passwords (w/ password manager) | 80 bits | 80+ bits |
| Encryption keys | 128 bits | 128+ bits |
| API keys / service tokens | 80 bits | 80+ bits |
| WiFi passwords | 60 bits | 80+ bits |
Introduction
How strong is your password, really? Not 'it looks complicated' — how many bits of entropy does it actually contain? The Entropy Calculator measures the true randomness of any input string using Shannon entropy, the same mathematical framework Claude Shannon pioneered in 1948 to quantify information. Paste a password, a passphrase, a PIN, or any string, and get an instant readout of its entropy in bits, its estimated crack time at various attack speeds, and a breakdown of its character distribution. This is the tool that replaces gut feelings with mathematics.
What This Tool Does
Why It Matters
Not all 'strong-looking' passwords are equally secure. A 16-character password with predictable patterns (like 'passwordpassword') has far less entropy than a random 12-character string. Shannon entropy measures the actual information content of your input by analyzing character frequency distribution — it quantifies how unpredictable your string truly is. A password with 80 bits of entropy would take a GPU cluster billions of years to crack; one with 30 bits could fall in minutes. Understanding entropy is the difference between thinking you're secure and knowing you are.
How It Works
Step-by-Step Examples
Paste the password 'k9$mPx2#nLq!vR7@wYz' into the input field
The calculator analyzes the character frequency distribution across all 20 characters
It computes Shannon entropy: H = -Σ p(x) × log₂(p(x)) for each unique character
The result shows both Shannon entropy and estimated entropy based on character pool size
Shannon entropy: 4.23 bits/char × 20 chars = 84.6 bits | Pool-based estimate: 20 × log₂(95) = 131.4 bitsEnter a weak password: 'aaaaaaaaaaaaaaaa' (16 lowercase a's)
Note the Shannon entropy: very low because there's only 1 unique character repeated 16 times
Now enter a random 16-character password with mixed characters
Compare: the random password has dramatically higher entropy despite identical length
Weak: Shannon 0.0 bits (1 unique char) | Strong: Shannon ~4.2 bits/char × 16 = ~67 bitsCode Examples
function shannonEntropy(str) {
if (!str) return 0;
// Count character frequencies
const freq = {};
for (const char of str) {
freq[char] = (freq[char] || 0) + 1;
}
// Calculate Shannon entropy: H = -Σ p(x) × log₂(p(x))
let entropy = 0;
const len = str.length;
for (const count of Object.values(freq)) {
const p = count / len;
entropy -= p * Math.log2(p);
}
return {
shannonBitsPerChar: entropy,
totalShannonBits: entropy * str.length,
uniqueChars: Object.keys(freq).length,
totalChars: len,
charDistribution: freq
};
}
// Usage
const result = shannonEntropy('k9mPx2nLq');
console.log(result.shannonBitsPerChar); // ~3.17 bits/char
console.log(result.totalShannonBits); // ~28.5 bits
console.log(result.uniqueChars); // 9function analyzePasswordEntropy(password) {
// Shannon entropy (actual information content)
const freq = {};
for (const char of password) freq[char] = (freq[char] || 0) + 1;
let shannon = 0;
for (const count of Object.values(freq)) {
const p = count / password.length;
shannon -= p * Math.log2(p);
}
// Pool-based entropy (theoretical maximum)
const hasLower = /[a-z]/.test(password);
const hasUpper = /[A-Z]/.test(password);
const hasDigit = /[0-9]/.test(password);
const hasSymbol = /[^a-zA-Z0-9]/.test(password);
let poolSize = 0;
if (hasLower) poolSize += 26;
if (hasUpper) poolSize += 26;
if (hasDigit) poolSize += 10;
if (hasSymbol) poolSize += 33;
const poolEntropy = password.length * Math.log2(poolSize || 1);
// Crack time estimates
const hashesPerSec = 1e12; // 1 trillion (large GPU cluster)
const combinations = Math.pow(poolSize, password.length);
const secondsToCrack = combinations / 2 / hashesPerSec;
return {
length: password.length,
uniqueChars: Object.keys(freq).length,
shannonBitsPerChar: shannon.toFixed(2),
totalShannonBits: (shannon * password.length).toFixed(1),
poolBasedBits: poolEntropy.toFixed(1),
poolSize,
crackTime: formatTime(secondsToCrack),
strength: poolEntropy > 80 ? 'Very Strong' : poolEntropy > 60 ? 'Strong' : poolEntropy > 40 ? 'Moderate' : 'Weak'
};
}
function formatTime(seconds) {
if (seconds < 1) return 'Instant';
if (seconds < 60) return seconds.toFixed(1) + ' seconds';
if (seconds < 3600) return (seconds / 60).toFixed(1) + ' minutes';
if (seconds < 86400) return (seconds / 3600).toFixed(1) + ' hours';
if (seconds < 31536000) return (seconds / 86400).toFixed(1) + ' days';
return (seconds / 31536000).toExponential(1) + ' years';
}
// Usage
console.log(analyzePasswordEntropy('password123'));
// { strength: "Weak", totalShannonBits: "28.5", poolBasedBits: "52.5" }
console.log(analyzePasswordEntropy('k9$mPx2#nLq!vR7@'));
// { strength: "Very Strong", totalShannonBits: "~65", poolBasedBits: "105.1" }Shannon Entropy vs Pool-Based Entropy
| Metric | What It Measures | Best For | Limitation |
|---|---|---|---|
| Shannon Entropy | Actual information content based on character frequency | Analyzing real-world passwords with patterns | Doesn't account for character pool — 'aaaa' and 'AAAA' score similarly |
| Pool-Based Entropy | Maximum entropy assuming uniform random selection | Evaluating generated passwords | Overestimates if the password has patterns or repetitions |
| Combined Analysis | Both metrics together | Comprehensive password assessment | Requires both calculations to be meaningful |
Entropy Reference Values
| Entropy (bits) | Example | Crack Resistance | Security Level |
|---|---|---|---|
| 20 | 4-digit PIN | Instant (10,000 combinations) | Very Weak |
| 30 | Common English word | Seconds to minutes | Weak |
| 40 | Short random lowercase | Minutes to hours | Moderate |
| 60 | 8-char mixed case | Days to years | Strong |
| 80 | 12-char full ASCII | Billions of years (1T h/s) | Very Strong |
| 100 | 15-char full ASCII | 10^18 years | Extremely Strong |
| 128 | 20-char full ASCII | Heat death of universe | Maximum Practical |
Benefits
- Calculates both Shannon entropy and pool-based entropy for a complete picture of password strength.
- Shows character frequency distribution so you can see exactly where entropy is gained or lost.
- Provides estimated crack time at multiple attack speeds: online (100/s), offline (1M/s), and GPU cluster (1T/s).
- Works on any input — passwords, passphrases, PINs, API keys, encryption keys, or arbitrary strings.
Use Cases
Evaluating the true strength of existing passwords to determine which ones need to be replaced.
Comparing entropy across different password generation strategies to choose the most effective approach.
Auditing password policies by testing sample passwords against entropy thresholds for different security levels.
Educating users on password strength by showing concrete entropy numbers instead of vague 'strong/weak' labels.
Common Mistakes to Avoid
Relying only on pool-based entropy and ignoring Shannon entropy — a password like 'aaaaaaaaaaaaaaaa' has pool-based entropy of 75.2 bits but Shannon entropy of 0 bits.
Assuming length alone guarantees strength — 20 characters of a repeated pattern have far less entropy than 12 truly random characters.
Using Shannon entropy as the sole metric — it measures information content, not resistance to targeted dictionary attacks.
Ignoring the difference between theoretical and practical entropy — a generated password may have 105 bits of pool entropy, but if you typed it yourself, human bias reduces actual entropy.
Security Implications
Entropy is the fundamental measure of password security. A password with 80+ bits of entropy is computationally infeasible to crack with current technology, while one with 30 bits can be brute-forced in seconds. Shannon entropy reveals patterns that pool-based calculations miss — a repeated character string may look long and complex but contains almost no actual information. Understanding both metrics is essential for accurately assessing whether your credentials can withstand offline brute-force attacks, which can now test billions of hashes per second on consumer GPU hardware.
Security Information
Frequently Asked Questions
When Should I Use This?
Measuring password strength in bits
Calculate the exact entropy of a password to understand its theoretical strength.
Comparing password candidates
Evaluate multiple password options and choose the one with the highest entropy.
Understanding character pool impact
See how adding different character types (uppercase, digits, symbols) increases entropy.
Educational demonstration
Learn about entropy calculation and password strength through interactive examples.
When Should I NOT Use This?
For overall strength assessment
Entropy is just one aspect of password strength. Use the Password Strength Checker for comprehensive scoring.
To check if a password has been breached
Entropy doesn't indicate breach status. Use the Breach Checker for that.
To generate new passwords
This tool calculates entropy, it doesn't create passwords. Use the Password Generator for new passwords.
What is Password Entropy?
Password entropy measures the unpredictability of a password in bits. It quantifies how many possible combinations an attacker would need to search through to find your password. The higher the entropy, the stronger the password.
Entropy is calculated using the formula E = L × log₂(R), where L is the password length and R is the size of the character pool. For example, a 12-character password using lowercase letters (R=26) has 12 × log₂(26) = 56.4 bits of entropy. Adding uppercase letters, digits, and symbols increases R, which increases entropy per character.
What the Results Mean
Below 28 bits (Very Weak): Can be cracked instantly. These passwords offer no meaningful protection.
28–39 bits (Weak): Crackable in minutes to hours with offline attacks. Not suitable for any account.
40–59 bits (Moderate): May resist online throttled attacks but vulnerable to offline GPU attacks. Marginally acceptable for low-risk accounts.60–79 bits (Strong): Resists most offline attacks for practical timeframes. Suitable for most accounts when combined with unique passwords.
80+ bits (Excellent): Computationally infeasible to crack with current technology. Ideal for master passwords, encryption keys, and critical accounts.
When to Use This Tool
Before setting a new password: Verify that your chosen password has sufficient entropy for the account's security requirements.
When evaluating existing passwords: Check whether passwords you currently use provide adequate protection against offline attacks.
When comparing password strategies: Compare the entropy of passphrases versus random character strings to understand which approach provides better security for your use case.
For security auditing: Assess whether passwords across an organization meet minimum entropy thresholds for different risk tiers.
Limitations
Theoretical estimate only: Entropy assumes truly random character selection. Human-chosen passwords follow predictable patterns (dictionary words, keyboard walks, personal information), which dramatically reduce effective entropy even if the calculated value appears high.
Does not detect dictionary words: A password like "password" with mixed case may show moderate entropy but is trivially guessable. Use the Password Strength Checker for pattern-aware analysis.
Attack speed varies: The crack time estimates assume specific attack speeds. Real-world speeds depend on the hashing algorithm used by the target system (bcrypt, Argon2, etc.).
Does not check breach databases: A high-entropy password that has appeared in a data breach is still compromised. Use the Breach Checker to verify.
Related Password Analysis Tools
Combine entropy analysis with these tools for a complete security assessment:
- Password Entropy Calculator — Quick entropy checks with strength recommendations and interactive experiments.
- Password Strength Checker — Overall strength score with pattern detection and breach checking.
- Password Character Analyzer — Detailed breakdown of character types and composition.
- Password Crack Time Estimator — Estimate crack time under different attack scenarios.
- Password Generator — Create high-entropy passwords using cryptographic randomness.
- Passphrase Generator — Generate memorable passphrases with strong entropy.