A worked example, rendered from real sample data. Sign in to run the tool on your own input.
Qwerty12345!═══ Three different numbers, three different meanings ═══
Shannon entropy: 3.585 bits per character (43.0 bits total)
• Measures only how varied THIS string is. "abababab" and a truly random 8-character string can score the same. It is not a strength figure.
Charset entropy: 78.8 bits
• 12 characters drawn from a 95-character pool, assuming every character was picked uniformly at random. This is the number password meters quote.
Realistic guessing entropy: 22.1 bits
• Charset entropy minus what a cracking rule set gets for free from the patterns found below.
═══ Composition ═══
Length: 12 characters
Distinct characters: 12 (100% of the length)
Lowercase a-z: 5 characters (+26 to the pool)
Uppercase A-Z: 1 character (+26 to the pool)
Digits 0-9: 5 characters (+10 to the pool)
ASCII symbols: 1 character (+33 to the pool)
Space: none
Search pool: 95 characters
═══ Patterns a cracker gets for free ═══
⚠ a 6-character keyboard walk — worth roughly 27.3 bits to a rule-based attack.
⚠ a 5-character alphabetical or numeric run — worth roughly 22.3 bits to a rule-based attack.
⚠ a capital letter only in first position, which is what almost everyone does — worth roughly 3.6 bits to a rule-based attack.
⚠ a single trailing symbol, the most predictable place to put one — worth roughly 3.6 bits to a rule-based attack.
Total discount applied: 56.7 bits.
═══ Time to guess (charset entropy) ═══
Online, rate limited: longer than the age of the universe
• 100 guesses per second against a login form with no lockout
Offline, bcrypt cost 12: longer than the age of the universe
• 20 thousand
…
Shannon, charset and realistic guessing entropy side by side, with the patterns discounted. Part of the DevTools Surf developer suite. Browse more tools in the Security / Crypto collection.