You've seen the rules: at least 8 characters, one capital, one number, one symbol. So people type P@ssw0rd!, the website shows a green "strong" bar, and everyone feels safe. They shouldn't. This page shows, with real arithmetic you can play with, why length matters far more than funny characters, how attackers actually guess, and what to do instead.

How a password gets cracked

When you sign up somewhere, a well-built website doesn't store your password itself. It stores a hash: the output of a one-way scrambling function. When you log in, the site hashes what you typed and compares the two scrambles. Nobody, not even the site, can turn the hash back into your password.

But websites get hacked, and lists of hashes leak. An attacker who has the leaked list can't "unscramble" them, so they do the only thing left: guess. Take a candidate password, hash it, see if it matches. Repeat billions of times. This is called an offline attack, because it happens on the attacker's own computers, with no login page to slow them down and no "too many attempts" lockout.

How fast is that? It depends on the hash. Old, fast hashes like MD5 were designed for speed, and a single modern gaming graphics card can try tens of billions of them per second. Good sites use deliberately slow hashes (like bcrypt or Argon2) that cut this to thousands per second. In this article we'll assume 10 billion guesses per second, a realistic figure for a leaked list of fast hashes, and you can switch to other speeds in the calculator.

Counting the possibilities

Suppose an attacker knows nothing about you and has to try every possible password. How many are there? It's the same maths as a bike lock. A lock with 4 dials of 10 digits has 10 × 10 × 10 × 10 = 104 = 10,000 combinations. In general:

possibilities = (characters to choose from) ^ (length)

The "characters to choose from" is called the character set. On a normal keyboard you have 26 lowercase letters, 26 uppercase, 10 digits and 32 symbols like !@#$%. Use all of them and each position has 94 options.

Now notice where the two numbers sit in that formula. The character set is the base; the length is the exponent. Making the base bigger helps a bit. Making the exponent bigger multiplies the whole thing again for every extra character. That's the entire argument of this article in one line. Play with it:

Brute-force calculator · random passwords

8

character sets

attacker speed (assumed)

possibilities
bits of entropy
time to try them all

Try the presets. Eight characters using every character set gives about 6 quadrillion possibilities, which a fast-hash attacker exhausts in about a week. Sixteen characters of plain lowercase letters, no capitals, no digits, no symbols, takes about 138,000 years. Doubling the length beat more than tripling the character set, by a huge margin.

Bits: a simpler way to say "how many"

Numbers like 4.4 × 1022 are hard to compare in your head, so security people use bits of entropy instead. "Entropy" here just means "how unpredictable". A password with n bits is as hard to guess as flipping a coin n times and guessing every flip: there are 2n possibilities.

Each character adds the same number of bits, so you can simply add them up:

each character drawn frombits per character
digits only (10)3.3
lowercase letters (26)4.7
letters + digits (62)5.95
everything on the keyboard (94)6.55
one word from a 7,776-word list12.9

Going from lowercase-only to the full keyboard raises each character from 4.7 to 6.55 bits, not even 2 bits more. Adding one more lowercase character adds 4.7 bits. And every extra bit doubles the attacker's work. Ten extra bits is about a thousand times more work; twenty is about a million times.

The fine print: all of this assumes each character (or word) is picked at random, say by dice or by a computer. That's what the calculator measures. Humans don't pick at random, and that changes everything.

Why P@ssw0rd! is weak

By the formula, P@ssw0rd! looks great: 9 characters from all 94, about 59 bits, nearly two years to brute-force. In reality it falls in well under a second. Attackers don't start at aaaaaaa and count upward. They start with what people actually choose. This is a dictionary attack, and it works in layers:

Every one of those "complexity" tricks is a rule in the attacker's playbook. The capital P, the @, the 0 and the ! each add about one bit of real surprise, because they're exactly what everyone does. Complexity rules made passwords harder for you to remember and barely harder for them to guess. That's why the US standards body NIST now tells websites to stop forcing symbol-and-capital rules and to focus on length and on blocking known-leaked passwords instead.

Type something below to see which patterns a guesser would spot. Try the examples, or your own made-up ones.

Pattern checker

🔒 Runs entirely in your browser. Nothing you type here is stored or sent anywhere: the page has no network access at all. Still, the safest habit is to never type a real password into any website that isn't the one it belongs to, so test with made-up examples.

if it were random
rough real-world guess
verdict
at 10 billion guesses/s

This is a teaching toy with a small built-in word list, not a real strength meter. "No patterns found" here does not prove a password is safe; real cracking dictionaries are millions of words long.

Look at Tr0ub4dor&3 versus correct horse battery staple (the famous example from the xkcd comic). The first looks scary and is mostly a dictionary word in disguise. The second is four plain words, and the checker knows they're words and treats each one as a single dictionary guess, and it still comes out far stronger, simply because it's long.

Passphrases: long and memorable

A passphrase is a password made of several random words, like orbit-velvet-canyon-pickle-sauna. The security comes from the fact that the words are chosen randomly, not from the words being secret. Even if the attacker knows your exact method and your exact word list, they still face 7,7765 ≈ 2.8 × 1019 possibilities for five words, about 65 bits.

The 7,776 figure comes from Diceware: roll five ordinary dice, read the numbers as e.g. 4-2-6-1-3, and look that up in a list of 65 = 7,776 words. Dice are truly random; your brain isn't. "My favourite band plus my street" is not a random passphrase.

Password managers and the one rule that matters most

Here's the uncomfortable truth: the strongest password in the world is useless if you also used it on a forum that got hacked. Attackers take leaked email-and-password pairs and try them on email, banking and shopping sites automatically. This is called credential stuffing, and it works because people reuse passwords. Rule number one: never reuse a password.

Nobody can remember 150 different long passwords, and you shouldn't try. A password manager (built into your browser or phone, or a dedicated app) generates a long random password for every site, stores them encrypted, and fills them in for you. You only memorise one strong passphrase to unlock it. Bonus: a password manager won't fill your password into a fake look-alike site, which protects you from phishing too.

Then, for important accounts (email above all, because it can reset every other password), switch on two-factor authentication: a second check, like a code from an app, so a stolen password alone isn't enough.

Check yourself

Which has more possibilities, if every character is picked at random?

A is 9410 ≈ 5.4 × 1019 (65.5 bits). B is 2614 ≈ 6.5 × 1019 (65.8 bits). Four extra plain letters beat adding capitals, digits and every symbol.

You add one more random lowercase letter to a password. What happens to the attacker's work?

Every possibility now has 26 ways to continue, so the count is multiplied by 26 (about 4.7 more bits). That multiplication is why length wins.

Sunshine2024! has 13 characters from all four sets. Why is it still weak?

Dictionary attacks try common words with capitalised first letters, years and a trailing ! early on. The structure is so predictable that its real strength is a tiny fraction of the 85 bits the formula suggests.

Your 6-word random passphrase is very strong. Is it OK to use it for both email and an online shop?

If the shop is breached (and stores it badly), the attacker gets the passphrase itself and tries it on your email. Strength doesn't help against reuse. Use a password manager so each site gets its own.

The short version