« Your password must contain 8 characters, an uppercase letter, a lowercase letter, a number, and a special character. »
We all know this rule. And yet, in cybersecurity, this is what we call “security theater.” A password like P@ssw0rd1! complies with all these rules. But it is a common word with predictable substitutions, which is exactly what cracking tools try first.
True security does not rely on arbitrary visual rules, but on an unforgiving mathematical reality: entropy.
Entropy according to Claude Shannon
To understand the strength of a password, we must look to Claude Shannon, the father of information theory. Entropy measures the degree of uncertainty or unpredictability of information.
Applied to passwords, entropy is calculated in bits. The higher the number of bits, the more unpredictable the password is for a computer. The simplified formula for the entropy (E) of a randomly generated password is:
E = L × log2(R)
- L is the length of the password.
- R is the pool size (26 for lowercase, 62 with uppercase and numbers, 94 with every printable symbol). Our generator’s four character sets give 91, because its symbol set has 29 characters.
Increasing the pool size (adding symbols) increases entropy, but increasing the length (adding characters) increases it much more drastically. However, length only beats complexity on one condition: the password must be generated completely randomly.
Brute Force vs. Dictionary Attack
If you use words or predictable structures, the rule of pure length collapses.
Hacking software does not try all letter combinations one by one (this is called Brute Force). They use huge lists of real passwords from past leaks, along with common words and phrases. This is the Dictionary Attack.
If your password is long, but composed of dictionary words or predictable substitutions, its actual entropy is dramatically lower than its theoretical mathematical entropy.
The table below uses one rule: 100 billion guesses a second, the rate our generator’s page assumes for an offline attack on a fast hash. Times are averages (half of all possibilities), rounded down with the same formula as that page. The fastest route for each password is in bold:
| Password | Entropy if every character were random | Brute force (average) | Dictionary attack (our estimate) |
|---|---|---|---|
password123 | 56 bits (11 characters, lowercase and numbers) | 7 days | Under a second |
S3cr3t!99 | 58 bits (9 characters, all four sets) | 24 days | Under a second |
correct horse battery staple | 133 bits (28 characters, lowercase and space) | More than 1 trillion years | 1 minute |
gL7!pQ9z#vX2 | 78 bits (12 characters, all four sets) | 51 thousand years | No shortcut |
The dictionary column is an estimate. It assumes the attacker’s guesses follow each password’s structure, and that each base word is among the 1,000 most common:
password123: one common word and three digits. That is 1,000 × 1,000, about a million guesses.S3cr3t!99: one common word, with or without a capital, each “e” swapped for “3” or not, then any three-character suffix. That is about 7 billion guesses.correct horse battery staple: four common words. The xkcd comic that made it famous counts 44 bits for four words from a list of 2,048. At the same rate, that is 88 seconds on average, rounded down to 1 minute.gL7!pQ9z#vX2: no word and no pattern, so brute force is the fastest route.
These estimates treat each password as unknown to the attacker. Every password in this article is now public, so each one belongs in a dictionary. A published password is a burned password.
The Illusion of Leetspeak and Mutation Rules
Take the example S3cr3t!99. Visually, it looks complex and robust. Yet, it is simply the dictionary word “secret”, where the ’e’s have been replaced by ‘3’s, to which a very common suffix has been added (!99). This is called leetspeak.
Against a dictionary attack, this password holds for under a second, not the 24 days its length would suggest. Modern cracking software (like Hashcat) does not just test static word lists; they automatically apply mutation rules. They will take every word in their dictionary, test all possible leetspeak combinations, swap uppercase letters, and append years or symbols. Leetspeak provides a false sense of security.
The Keyboard Shift Trick
To complicate a memorable phrase, some use the keyboard layout shift trick. For example, you memorize a phrase like my-cat. But when typing it, you place your fingers on a physical QWERTY keyboard while having your operating system configured to AZERTY (French).
- The intended word:
my-cat - The typed result:
,y)cqt(The ’m’ key becomes ‘,’; the ‘-’ becomes ‘)’; the ‘a’ becomes ‘q’).
Is this a good OPSEC idea? No, this method is not enough if used alone. Just like leetspeak, a layout shift is a fixed substitution: an attacker who suspects it applies the same mapping to every guess. In OPSEC, this is security by obscurity: it delays an amateur attacker, but will not stop a targeted and equipped attack.
Coupled with a password that is already strong (like a long random passphrase), it adds little. Even if an attacker tries a thousand layout pairs, that adds under 10 bits, since log2(1,000) ≈ 9.97. The strength still comes from the passphrase underneath.
Building a Master Password (~250 bits)
If word lists, leetspeak, and typing tricks have their limits, how do we build a master password that lasts? Our generator already rates 80 bits Strong and 100 bits Very Strong. For a master password meant to last for decades, this article aims far higher: around 250 bits of entropy. The quantum section below explains why, and what that margin does not buy.
There are two ways to achieve this depending on your needs:
1. Random Characters (for a password manager)
A character string generated entirely at random, with no pattern for a machine to exploit:
8}8,_$-p)M&n,XvUCT0o+.5hDE6P^w6b@U-evS0
39 characters drawn at random from our generator’s 91: ≈ 253 bits. It was drawn for this article, so it is now public. Never use it.
2. A Random Passphrase (for a password you memorize)
Random words are easier to remember than random characters. Each word drawn from the EFF list of 7,776 words adds about 12.9 bits, so the word count gives the entropy. Twelve words give ≈ 155 bits, far above our generator’s Very Strong threshold. Plain words only pass 250 bits at 20 words.
Our generator stops at 12 words. To pass 250 bits with fewer, tick “Random digit after each word” and choose “Random Digit + Symbol” as the separator. Eleven words then give ≈ 260 bits:
depletion78$sporting14~overlap11>macaw86>paced95,paramedic41}blot41$flagstone07;uncanny92/broadways77#say2
Drawn at random for this article, with exactly those settings. A published password is a burned password: never use this one, or any example you read. Only what is drawn at random counts. Capitalizing every word adds nothing, and words you pick yourself are far weaker than random ones.
The Quantum Threat: Grover’s Algorithm
Why aim for 250 bits when 128 bits already block today’s supercomputers? The answer lies in the prospect of large quantum computers.
In cryptography, Grover’s algorithm allows a quantum computer to search an unsorted database much faster than a classical computer. Concretely, Grover effectively halves the security level of a symmetric key or a password.
Against a quantum computer running Grover’s algorithm, a password with an entropy of 128 bits would, in theory, offer a resistance equivalent to only 64 bits. That is a much thinner margin.
Doubling the entropy keeps the margin: about 256 bits would still leave about 128 bits against Grover. That is where this article’s 250-bit target comes from. It is a precaution this article chooses, not a figure taken from a standard.
The margin has limits. Grover’s speed-up is quadratic, not unlimited. Each of its steps still has to compute the site’s password hash, on a quantum computer large enough to run it. For comparison, at the 100 billion guesses a second that our generator’s page assumes, an average search of 100 bits already takes at least 200 billion years.
The logic resembles Harvest Now, Decrypt Later (HNDL): a stolen database of password hashes can be kept today and attacked later, with better machines. A larger margin raises the bar against that. It is not a permanent guarantee.
Arpokrat Password Generator: Make Your Own
Do not leave the security of your access to chance. Our free generator makes random passwords and passphrases. For each one, it shows the entropy in bits and the average time a search would take.
It only generates: it does not rate a password you already use. For the 250-bit target above, choose a 39-character password with all four character sets. The generator shows it as ≈ 253 bits.
It runs in your browser. What it generates is never sent or saved.
The Final Weak Link: Recycling and Access Management
Mathematical entropy does not protect against human error. A 250-bit password loses its value once it leaks, if it is reused on multiple sites (an attack called Credential Stuffing) or if it is not protected by a second authentication factor (2FA).
The golden rule of digital hygiene is to only have to remember one single password: your 250-bit master password (a random passphrase, as above). All your other accesses (bank, social networks, servers) must use unique random passwords, generated specifically for them.
To store all these passwords you cannot remember, use a password manager. Choose one that encrypts your vault on your device before syncing it (often called zero-knowledge), ideally one that is open source and independently audited.
