Password Strength & Crack-Time Entropy Auditor
Analyze password strength, calculate Shannon entropy in bits, audit dictionary patterns, and estimate brute-force cracking resistance across consumer GPUs, server arrays, and quantum supercomputers.
Password Security & Crack-Time Auditor
Type a password in the box above to analyze its Shannon entropy (bits), character composition, and estimated time to crack via GPU clusters and supercomputers.
Security Rating: Very Weak
Estimated Brute-Force Crack Times
Character Pool Composition
Vulnerability & Pattern Audit
- No obvious dictionary patterns or sequence vulnerabilities detected.
NIST SP 800-63B Password Security Guidelines
Modern authentication standards set by NIST emphasize length over complex composition rules (e.g. forced symbols), prioritizing long passphrases and resistance to dictionary attacks.
NIST Password Guidelines
- Length Threshold: Minimum 8 characters; 16+ characters recommended for administrator accounts.
- No Arbitrary Expiration: Periodic password rotation is discouraged unless a compromise is suspected.
- Breached Password Check: Passwords should be checked against known data breach lists (e.g. HaveIBeenPwned API).