Password entropy: how long is long enough, and what symbols really add
A password meter turns green when you add an exclamation mark, and the advice to “use symbols” has outlived the reasoning behind it. The reasoning is a formula you can run yourself, and it shows that length usually does more work than the character mix.
Entropy is a count of possibilities
If every character of a password is drawn uniformly at random from a pool of N characters, there are
N^length possible passwords, and the entropy in bits is:
bits = length × log2(N)
Each bit doubles the search space. The per-character figures for common pools:
| Pool | Size | Bits per character |
|---|---|---|
| Digits | 10 | 3.32 |
| Lowercase | 26 | 4.70 |
| Lowercase + digits | 36 | 5.17 |
| Letters, both cases | 52 | 5.70 |
| Letters + digits | 62 | 5.95 |
| Letters + digits + the 28 symbols the generator offers | 90 | 6.49 |
The difference between the first and last row is about a factor of two per character, so no pool choice buys more than that. Length multiplies, and 20 characters from the 90-character pool come to about 129.8 bits.
Symbols add half a bit per character, a longer password adds six
Going from 62 characters to 90 raises each character from 5.95 to 6.49 bits, a gain of 0.54. Over a 16-character password that is about 8.6 bits. One more character at the 62-character pool adds 5.95 bits. Compare two ways of spending the same typing effort:
| Choice | Entropy |
|---|---|
| 16 characters, letters and digits | 95.3 bits |
| 15 characters, all four classes | 97.4 bits |
| 12 characters, all four classes | 77.9 bits |
| 14 characters, letters and digits | 83.4 bits |
So symbols are worth a little, and they pay for themselves mainly when a site caps the length. When you
have no cap, adding two characters is the cheaper gain. Symbols also carry a cost the formula ignores:
some sites reject certain ones, and a shell, a URL or a config file may mangle a $ or a \. A longer
password of letters and digits survives all of that.
Lowercase-only deserves its own line. It needs 18 characters to pass 80 bits (17 reach 79.9), where the 90-character pool needs 13.
Where the pool really comes from
The pool is whatever the generator can pick from, not whatever the finished password happens to contain. If
symbols were available and a particular password happened to contain none, the pool was still 90. The generator on this site computes length × log2(pool) from the pool after
every exclusion, deduplicated, so typing a character that is already in the pool adds nothing.
The “no look-alikes” option removes I, l, 1, O, 0 and |. That takes the full pool from 90 to
84, so a 20-character password drops from 129.8 to about 127.8 bits: a small price when you have to read
a password aloud or copy it from paper.
Why Math.random is unfit
Math.random() makes no promise of unpredictability. The language specification asks for values that
look uniform, and says nothing about whether someone who has seen a few outputs can predict the next ones.
A password generator needs the second property. Browsers provide it as crypto.getRandomValues, a
cryptographically secure generator seeded from the operating system. The password tool uses that and
refuses to run if the function is missing, rather than quietly falling back.
Using a good generator is not enough, because the common way of turning a random byte into a character index is biased:
const index = byte % pool.length; // biased
A byte has 256 values. With a 62-character pool, 256 = 4 × 62 + 8, so characters 0 to 7 are reachable from five byte values and the other 54 from four. The first eight characters come up 25% more often. The fix is rejection sampling: accept only bytes below the largest multiple of the pool size (248 for 62 characters, 180 for 90) and draw again otherwise. Redraws are not rare: with a 90-character pool about 30% of bytes are thrown away (76 of 256). That is cheap, and it is what keeps every character equally likely, which is the assumption the entropy formula rests on.
What “one of each class” does to the number
Sites that demand a digit and a symbol are satisfied by a generator option that forces at least one character from each selected class. The generator does this by reserving random positions for those characters and filling the rest from the whole pool. The result is no longer a perfectly uniform draw, because passwords with no digit can never occur, so the displayed bits are a slight over-estimate. The loss is small for a long password, where most unconstrained draws would have contained every class anyway, and larger for a short one with four classes demanded. If the site does not insist, turn the option off and the figure is exact.
The tool also states a floor: it refuses a length shorter than the number of classes you demand, instead of silently dropping a class.
What the number does not tell you
Entropy describes how a password was chosen, and the formula only holds for uniform random choice. Three limits follow.
- Human-made passwords do not qualify.
Tr0ub4dor&3looks like a 90-pool, 11-character password but was derived from a dictionary word with predictable substitutions, so its real entropy is far lower than11 × 6.49. Substituting characters in a word only helps against an attacker who does not know the habit. - Reuse beats entropy. A 130-bit password used on two sites is as strong as the weaker site’s storage. If one of them leaks it, the other falls, regardless of the bit count. The tool’s own note says not to reuse a generated password; let a password manager hold one per account.
- A compromised device sees everything. A keylogger or malicious extension reads the password as you type or copy it. Entropy protects against guessing, not against theft.
The labels in the generator (weak under 45 bits, fair to 63, good to 79, strong from 80) are a convenient scale, not a measured threat model. How many bits you need depends on whether an attacker can test guesses against a slow login form or against a stolen hash with their own hardware, and no formula here knows which.
Choosing a length
For an account protected by a password alone, 16 characters from the full pool is about 104 bits, which is comfortable. If a site caps you at 12, use all four classes and you still reach about 78 bits. With a password manager typing it for you, there is no reason to go short; the generator’s limit of 64 characters exists because some sites silently truncate longer input, and a truncated password is one you may not be able to type back in.
If you need something to memorise, a randomly chosen word sequence works on the same arithmetic: a 7,776-word list gives 12.9 bits per word, so six words come to about 77.5 bits. The generator on this site makes character passwords only, so for words you would need to roll dice or use a different tool.