Back to glossary

Entropy

Entropy measures how unpredictable a password or passphrase is — higher entropy means harder guessing attacks.

Last updated:

Entropy (in password security) estimates how many bits of unpredictability a secret contains. Roughly: if a generator could produce 2^N equally likely outcomes, the result has about N bits of entropy.

How it works

Think of entropy as the size of the haystack an attacker must search. A fair coin flip is 1 bit. A random digit (0–9) is a bit more than 3 bits. A character drawn uniformly from a 95-character printable set contributes about 6.5 bits. Multiply (add bits) across independent choices.

Human-chosen secrets rarely reach the theoretical maximum because people reuse patterns. That is why generated randomness matters more than “looking complex.”

Why it matters for passwords

Attackers who cannot phish you may still try guessing or brute-force. Higher entropy expands the search space. A long random password or a multi-word random passphrase both aim for enough entropy to make offline guessing impractical with current hardware budgets.

Practical example

A four-word passphrase drawn uniformly from a 7,776-word list (classic Diceware scale) has about 51 bits if separators add no extra choices — already far stronger than Summer2026!. A 16-character random password from a ~95-character set is much stronger still for vault-stored secrets you never type.

Related terms

Related reading

PassTip tip

Use longer lengths or more passphrase words when an account is high value. Generate locally: password generator or passphrase mode.