Tr0ub4dor&3 looks strong. correct horse battery staple looks weak. Entropy says the opposite — and entropy is right. Understanding this one concept permanently upgrades how you judge every password you'll ever create.
Entropy in one paragraph
Entropy measures unpredictability in bits. Each bit doubles the search space: 10 bits means ~1,000 possibilities, 40 bits means ~a trillion, 80 bits is beyond any brute force that will ever exist. A password's entropy comes from the size of the pool each unit is drawn from and the number of units — roughly, length × log₂(pool size). The key insight: entropy describes the generation process, not the string's appearance.
Related reading: How to Remain Valuable When Intelligence Becomes Cheap — a 224-page practical book on staying valuable as intelligence gets cheap. $3.84. Read it on Gumroad →
Why length beats complexity
Compare approaches. An 8-character password from 94 keyboard symbols: 8 × ~6.6 = ~53 bits. A 4-word passphrase from a 7,700-word list: 4 × ~12.9 = ~52 bits — similar strength, vastly more memorable. Now stretch the passphrase to 6 words: ~78 bits, and still typable. Adding one more word (~13 bits) beats doubling the symbol pool, because length multiplies while complexity only adds.
This is why complexity rules ("must contain a symbol!") backfire: they shrink what humans actually do to predictable substitutions (a→@) while making passwords harder to remember. Attackers know the substitutions. Length they can't dodge.
The catch: humans are predictable
Entropy math assumes random generation. A personally meaningful phrase — lyrics, quotes, ilovemydog2024 — has far less entropy than its length suggests, because attackers try meaningful phrases first. The fix is mechanical randomness: roll dice, use a generator, accept the weird word sequence. See passphrases vs password managers for how to deploy this in practice.
Estimate your own
The text entropy calculator measures the information content of any string, and the password strength analyzer estimates real-world crack resistance rather than just counting character classes. Test the passwords you're actually using — the results tend to be motivating.