Patterns, not just characters.
We use zxcvbn ↗ to recognize common words, repeats, dates, and keyboard patterns. The displayed bits are log₂ of its estimated guesses. Novel patterns and non-English text may be overestimated.
PASSWORD ENTROPY EXPLORER
Estimate the guesses. Model the attack time.
Find out what your password really brings to a derived key.
Enter a password. The analysis stays on your device.
LOAD A TEST CASE
Calculated in your browser. Never sent or saved by this app. Public examples are for learning, never for use as passwords.
Estimated guessing difficulty
Every bit represents a doubling of the estimated number of guesses.
Estimated time to crack
—
Estimated guesses ÷ assumed guessing rate. Illustrative rates, not benchmarks: hardware, hash and KDF settings can change the time dramatically. This is not a guarantee.
An estimate of guessability, not a measurement of true entropy. How the password was chosen matters.
03 / THE KEY DERIVATION LIMIT
A key derivation function can stretch a password into a 256-bit key. It can’t create additional secret entropy.
Enter a password to replace the 40-bit example with your estimate. A salt prevents reuse of precomputed attacks; a costly KDF slows each guess. Neither adds secret randomness.
We use zxcvbn ↗ to recognize common words, repeats, dates, and keyboard patterns. The displayed bits are log₂ of its estimated guesses. Novel patterns and non-English text may be overestimated.
True entropy depends on how a password was generated. For independent, uniform choices from an alphabet of N symbols, H = L × log₂(N). A string alone cannot establish those assumptions.
For a deterministic derivation with a known salt, H(key | salt) ≤ H(password), also bounded by the key length. Guessing difficulty and information entropy are different quantities.