How Password Entropy & Strength are Measured
Password strength is mathematically defined by its information entropy, measured in bits. Entropy calculation takes into account both the length of the string and the size of the character pool (lowercase, uppercase, numbers, and special symbols).
Key Strength Benchmarks
- Under 40 bits: Very Weak — crackable in milliseconds by commodity GPUs.
- 40 to 60 bits: Moderate — vulnerable to targeted dictionary attacks.
- 60 to 80 bits: Strong — resistant to offline brute-force attacks.
- Above 80 bits: Cryptographically Secure — computationally infeasible to crack.