Why log₂?
Each bit doubles the guesses an attacker needs. A pool of 95 symbols is
about log2(95) ≈ 6.6 bits per character, so every character
you add multiplies the difficulty by ~95.
Tools · Entropy
Entropy is unpredictability measured in bits. Enter a password to see the math worked out — character pool, length, and the resulting bits — all on your device.
| Length | 0 characters |
| Character pool size | 0 symbols |
| Bits per character (log2 pool) | 0 |
| Total entropy (length × bits/char) | 0 bits |
Calculated locally in your browser. No network, no logging, no telemetry.
Each bit doubles the guesses an attacker needs. A pool of 95 symbols is
about log2(95) ≈ 6.6 bits per character, so every character
you add multiplies the difficulty by ~95.
This math only holds if each character is chosen independently and uniformly. That’s precisely what a CSPRNG does and a human brain doesn’t — which is why a generated password’s real entropy matches its theoretical entropy.
For passphrases the unit of randomness is the word, not the character: entropy is words × log2(wordlist size). A 6-word passphrase from a 1,193-word list is ~61 bits. Build one with the passphrase generator.
Entropy is a measure of unpredictability, expressed in bits. Each additional bit doubles the number of guesses needed to brute-force the password. It is calculated as length × log2(character pool size) for a randomly chosen password.
The pool is the count of distinct symbols an attacker must consider: 26 for lowercase, 26 for uppercase, 10 for digits, and 33 for common ASCII punctuation. We add the sizes of whichever classes appear in your password.
Yes — the length × log2(pool) formula assumes each character is chosen independently and uniformly. A human-chosen password with dictionary words or patterns has much lower real entropy than this formula suggests, which is exactly why generated passwords are stronger.
≥80 bits is strong against offline brute-force in 2026, and ≥100 bits is future-proof. A 14–16 character password using all four character classes, chosen randomly, gets you there.
Ready for the full vault?
Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.