Passphrase Entropy Calculator
Estimate how many bits a word-based passphrase really has after separators, digits, symbols, known-word leakage, attacker speed, and key-derivation slowdown.
📌Home Lab Security Presets
🧮Passphrase Inputs
Passphrase Strength Results
Average crack time assumes the correct phrase is found halfway through the adjusted search space.
📊Current Input Breakdown
📘Reference Tables
| Word list | Size | Bits per word | Six random words |
|---|---|---|---|
| Diceware classic | 7776 | 12.9 bits | 77.5 bits before extras |
| EFF short list | 1296 | 10.3 bits | 62.0 bits before extras |
| EFF long list | 7776 | 12.9 bits | 77.5 bits before extras |
| Large app dictionary | 65536 | 16.0 bits | 96.0 bits before extras |
| Attack setting | Example speed | Best use | Calculator entry |
|---|---|---|---|
| Online login throttled | 1 to 10 guesses/sec | Web portals and VPNs | 10 |
| Slow vault KDF | 100 to 10000 guesses/sec | Password managers | 100000000000 with slowdown |
| Fast offline hash | 100 billion guesses/sec | Unsalted or weak hashes | 100000000000 |
| Large cracking rig | 10 trillion guesses/sec | High budget offline threat | 10000000000000 |
| Pattern choice | Entropy rule | Example | Caution |
|---|---|---|---|
| Random words | words x log2(list size) | 6 x 12.9 bits | Only true if selected randomly |
| Random separators | gaps x log2(separator set) | 5 gaps from 10 symbols | Fixed spaces add no bits |
| Known leaked words | subtract leaked word bits | Two known words remove two draws | Hints and themes matter |
| KDF slowdown | divide guesses per second | 1000000000x slower hash | Does not add entropy |
| Scenario | Typical inputs | Strength range | Practical note |
|---|---|---|---|
| Router local admin | 5 random words, slow login | 65 to 80 bits | Great when unique and stored safely |
| Password manager vault | 6 to 7 words, KDF enabled | 78 to 95 bits | Prefer random words over quotes |
| Guest Wi-Fi | 4 words, visible sharing | 45 to 60 bits | Rotate when guests change |
| Offline backup archive | 7 to 8 words, no reuse | 90 to 110 bits | Print recovery copies carefully |
🔍Password And Passphrase Comparison
💡Practical Tips
You often think of a long password as a strong password but nope. A longer password with nothing random in it is simply a bigger target for an attacker familiar with how dictionary attacks work. When you use a passphrase, meaning you pick words you like or string together a phrase that makes sense to you, you are creating something an attacker can anticipate.
And this thing above is here to bust that illusion, and reveal what’s really going on mathematically: how resistant your phrase is to being brute forced. It will force you to confront the gap between what is memorable and what is secure; often they is at odds.
How to Choose a Strong Passphrase
It’s a measure of entropy, in bits, which is NOT a scale between 0-100. Entropy measures the difficulty for an attacker to guess your secret, doubling number of guesses required for each extra bit. People often mistakenly believe that capitalization or other cosmetic changes greatly increase security (they don’t). An attacker would know if you capitalized start of string or added an exclamation mark. This makes them “fixed” rules instead of something the attacker has to guess.
So plugging in the dictionary size and word count into the calculator above spares you from converting and multiplying coefficients, as it does the entropy math for you. What it shows is that cosmetic complexity of the resulting string doesn’t really matter; actual strength derive solely from how many possible combinations exist within your word list.
Think about the attack vector: Is it protecting a local backup drive you toss in a drawer? Then you’re facing an offline attack with lots of computing power, which means speed isn’t as important; just raw randomness. But if it’s being used for logging into a website, then the server can slow them down by using a slow key derivation function (such as Argon2id), or simply throttle number of attempts. That’ll slow down the attacker by orders of magnitude.
What would of take centuries to crack offline could take only hours if hashes are not protected. The table of references on the page breaks this down; you’ll see what kind of rate guesses will be made from offline supercomputers, all the way up to online throttled attempts. It helps you know where you don’t want to go overboard, you don’t want to spend days coming up with a Wi-Fi passphrase, but then not care about your master vault’s protection.
The silent killer for passphrases is leakage. Have you used a word before? Are there any words personal to you (favorite book, dog’s name, etc.)? That reduces the search space for attackers, they don’t have to run through the entire dictionary. Just what you’re probably going to type. That means you can subtract those away with this calculator. It’s a linear penalty; if you leak two words then you lose the entropy of two random draws.
There’s no way to make up for leaked knowledge by introducing more guessable punctuation. You simply need to introduce some really random words.
These four words fit easily on your tongue, but they aren’t enough because many people will stop at four. With a typical dictionary of 7,776 words, four word amount to approximately 51 bits of entropy. That’s fine for lower-value accounts that won’t be stored in a sensitive database. For an encrypted archive or master password manager, though, go bigger. Six words (77ish bits) is considered strong for most home lab applications. Go with seven, and you’re pushing “vault” territory, more than 90 bits.
There’s a catch: Seven random words become more difficult to enter accurately and type corectly. You’ll have to weigh the security need against real-world inconvenience of using them every day.
Humans suck at producing random things. We love semantic connections, patterns, and rhymes. To our minds, a song lyric or a quote feels random. Yet these things is filled with structure. Before attackers ever reach random word lists, they’ll create dictionaries from common phrases, songs, and books. True randomness, whether from a cryptographically secure generator or just rolling some dice, eliminates that bias. Each word will have an equal shot at getting picked. That’s how you get the promised entropy in the calculator. Otherwise, your bits aren’t a promise, they’re an educated guess.
A secure system is not an endpoint; it’s a state maintained by assumptions. A passphrase can only be as strong as how well you keep it unique (and how good a job you do keeping it secret). Creating a strong passphrase that you use on more than one site shares some of the risk. If that site has a data leak, all of your other accounts might now be vulnerable.
To avoid this, store unique passphrases in a password manager. Make sure they’re long enough to withstand the computing power available today and likely for several years from now. Then forget them.
Security isn’t about making your data inconveniently hidden, it’s about making it mathematically inaccessible. Real security comes from unpredictable selection processes, not complex outputs.



