Password Strength Guide: Entropy & Crack Times
Most password advice — "use 8 characters, add a number" — is outdated and misleading. The real measure of a password's strength is its entropy: how many guesses an attacker must try, on average, to find it. This guide explains entropy and shows why length beats complexity.
What Is Password Entropy?
- characters — size of the character set used
- length — number of characters in the password
Each bit of entropy doubles the search space.
Common character-set sizes: lowercase = 26; + uppercase = 52; + digits = 62; + symbols ≈ 95.
Estimating Crack Time
Divide by 2 because, on average, half the space is tried before a hit.
Example: an 8-character password using all 95 printable symbols has entropy 8 × log₂(95) ≈ 52 bits. At 10 billion guesses/sec (offline GPU attack), that's 251 ÷ 1010 ≈ 2.25 × 105 seconds ≈ 2.6 days. A 12-character version: ~78 bits → ~1013 years.
Length Beats Complexity
Adding one character to a password multiplies the search space by the character-set size. Adding a symbol (going from 62 to 95 chars) only multiplies by ~1.5 per character. So a long password of random words (a "passphrase") is both stronger and easier to remember than a short scrambled one.
Four random common words (e.g. "purple-turtle-window-guitar") ≈ 52 bits of entropy — comparable to a complex 8-char password, but far easier to type and remember.
Real Attacks Aren't Brute-Force
Attackers use dictionaries, leaked-password lists, and pattern substitution (a→@, e→3). So "P@ssw0rd1!" — which looks complex — is actually weak because it's a known pattern. True strength comes from randomness, not from mangling common words.
A strong password is useless if it's leaked in a breach and reused elsewhere. Use a password manager to generate and store a unique random password for every site.
Put It Into Practice
Type or generate a password to see its entropy in bits and an estimated crack time at several attack speeds.
大多数密码建议——"使用8个字符,加一个数字"——已经过时且具有误导性。衡量密码强度的真正标准是其 entropy:攻击者平均需要多少次猜测才能找到它。本指南解释了entropy,并展示了为什么长度胜过复杂性。
什么是密码entropy?
- characters — 所使用的character set的大小
- length — 密码中的字符数
每增加一bit的entropy,搜索空间就会翻倍。
常见的character set大小:小写字母 = 26;加大写字母 = 52;加数字 = 62;加符号 ≈ 95。
估算crack time
除以2是因为平均而言,在找到正确答案之前,已经尝试了一半的空间。
示例:一个使用全部95个可打印符号的8字符密码,其entropy为8 × log₂(95) ≈ 52 bits。以100亿次猜测/秒(离线GPU攻击)的速度计算,即251 ÷ 1010 ≈ 2.25 × 105秒 ≈ 2.6天。一个12字符的版本:约78 bits → 约1013年。
长度胜过复杂性
给密码增加一个字符,搜索空间就会乘以character set的大小。添加一个符号(从62个字符增加到95个)只会使每个字符的搜索空间乘以约1.5。因此,一个由随机单词组成的长密码("passphrase")既更强又更容易记忆,而不是一个短而混乱的密码。
四个随机常见单词(例如 "purple-turtle-window-guitar")≈ 52 bits的entropy —— 与一个复杂的8字符密码相当,但更容易输入和记忆。
真正的攻击不是brute force
攻击者使用字典、泄露的密码列表和模式替换(a→@, e→3)。所以 "P@ssw0rd1!" —— 看起来很复杂 —— 实际上很弱,因为它是一个已知的模式。真正的强度来自随机性,而不是篡改常见单词。
一个强密码如果在数据泄露中被泄露并在其他地方被重复使用,就毫无用处。使用密码管理器为每个站点生成并存储一个唯一的随机密码。
付诸实践
输入或生成一个密码,查看其entropy(以bits为单位)和在几种攻击速度下的估计crack time。
Try the Password Strength Checker
Live entropy, crack-time estimates, and a built-in generator.
🔐 Open Password Checker →