Password entropy is a way to measure how many different password combinations are possible under a specific set of rules. It is usually expressed in bits.
Two things have the biggest effect on the number of possible passwords:
- The number of characters you can use
- The number of characters in the password
For example, a short PIN that uses only numbers has fewer possible combinations than a longer password that can use letters, numbers, and symbols.
The math behind password entropy becomes much easier when you start with a simple example.
How Password Combinations Are Calculated
Imagine a 4-digit PIN.
Each position can contain any number from 0 to 9. That gives you 10 choices for every position.
For four positions:
10 × 10 × 10 × 10 = 10,000
You can also write this as:
10⁴ = 10,000
So there are 10,000 possible four-digit PINs, from 0000 to 9999.
The same idea works for passwords.
The general formula is:
Possible combinations = Nᴸ
Here:
- N = number of characters available
- L = password length
For example, suppose a password can use 62 different characters and has 8 characters.
The calculation is:
62⁸ = 218,340,105,584,896
That means the rules allow more than 218 trillion different 8-character strings.
What Do N and L Mean?
The formula uses two simple values.
N: Number of Available Characters
N tells you how many different characters can be used in each position.
For example:
Lowercase letters: 26
Uppercase letters: 26
Numbers: 10
If all three are allowed:
26 + 26 + 10 = 62
So the character set contains 62 possible characters.
If symbols are added, the number of available characters becomes larger.
L: Password Length
L tells you how many characters the password contains.
For example:
6 characters → L = 6
8 characters → L = 8
12 characters → L = 12
So an 8-character password using 62 possible characters has:
N = 62
L = 8
That gives:
62⁸
possible combinations.
The Password Entropy Formula
For a password where each character is chosen independently and uniformly at random from the available character set, entropy can be calculated with:
H = L × log₂(N)
Here:
- H = entropy in bits
- L = password length
- N = number of available characters
You may notice that this formula looks more complicated than Nᴸ.
They are connected.
The first formula:
Nᴸ
tells you how many different passwords are possible.
The entropy formula:
H = L × log₂(N)
expresses the size of that same password space in bits.
So entropy is simply another way of describing the number of possible combinations.
Why Is Entropy Measured in Bits?
Bits are useful for describing very large numbers in a smaller form.
For example:
1 bit = 2 possible outcomes
because:
2¹ = 2
And:
2 bits = 4 possible outcomes
because:
2² = 4
And:
3 bits = 8 possible outcomes
because:
2³ = 8
The same idea works with passwords.
If a password space contains:
2²⁰ = 1,048,576
possible combinations, it can be described as:
20 bits
So when you see an entropy value in bits, it is simply another way of describing how large the possible password space is.
A Simple Four-Digit PIN Example
A four-digit PIN is a good way to understand the complete calculation.
There are:
10 possible digits
and:
4 positions
So:
10⁴ = 10,000 possible PINs
Now calculate the entropy:
H = 4 × log₂(10)
The result is approximately:
13.3 bits
The value 13.3 bits does not mean the PIN has 13.3 characters.
It means the 10,000 possible PINs can be represented as about 13.3 bits.
This is simply a different way of describing the same set of possibilities.
How Password Length Changes the Number of Possibilities
Now move from a PIN to a password.
Suppose a password generator allows 62 characters:
26 lowercase letters + 26 uppercase letters + 10 numbers
Keep this character set the same and change only the password length.
| Password Length | Possible Combinations | Approx. Entropy |
|---|---|---|
| 6 characters | 62⁶ = 56,800,235,584 | 35.7 bits |
| 8 characters | 62⁸ = 218,340,105,584,896 | 47.6 bits |
| 10 characters | 62¹⁰ = 839,808,609,443,436,096 | 59.5 bits |
| 12 characters | 62¹² = 3,226,266,762,397,899,821,056 | 71.5 bits |
The character set stays the same in every example.
Only the password length changes.
The number of possible passwords still grows very quickly.
For example, an 8-character password has:
62⁸
possible combinations.
Adding one more character gives:
62⁹
That new position can contain any of the 62 characters, so the previous number of combinations is multiplied by 62.
This is why adding password length has such a large effect.
How a Larger Character Set Changes the Result
Password length is only one part of the calculation.
The number of available characters also matters.
Suppose the password is 8 characters long in both cases.
Lowercase letters only
There are:
26 possible characters
So:
26⁸ = 208,827,064,576
Lowercase letters + uppercase letters + numbers
There are:
62 possible characters
So:
62⁸ = 218,340,105,584,896
Both passwords have the same length.
The difference is that the second password has more characters available for each position.
The entropy changes as well:
8 × log₂(26) ≈ 37.6 bits
8 × log₂(62) ≈ 47.6 bits
So adding more character choices increases the possible password space.
A Complete Password Entropy Example
Suppose a password generator allows:
26 lowercase letters
26 uppercase letters
10 numbers
That gives:
N = 62
Now set the password length to:
L = 12
First calculate the number of possible passwords:
62¹² = 3,226,266,762,397,899,821,056
Now calculate entropy:
H = 12 × log₂(62)
The result is approximately:
71.5 bits
So the password-generation rules create a very large possible password space.
The important part is understanding where that number comes from:
62 possible characters
combined with:
12 positions
Each position can use any of the 62 characters.
That is what creates the large number of possible combinations.
Why Randomness Matters
This is an important part of password entropy.
The formula assumes that the password characters are chosen randomly from the available character set.
Consider:
Summer2026!
The password contains letters, numbers, and a symbol.
But the way it was created is easy to describe:
Summer + 2026 + !
The person chose a familiar word, added a year, and then added a symbol.
Now compare that with:
q7M@2vL9#
This second example does not follow the same obvious pattern.
The difference is important because entropy calculations work best when the password is genuinely generated from the available character set rather than built around familiar information.
Why Character Variety Alone Is Not Enough
Using several character types does not automatically make a password random.
For example:
Welcome123!
contains:
- uppercase letters
- lowercase letters
- numbers
- a symbol
Even so, the password follows a familiar pattern:
common word + number + symbol
The character set may look large, but the person did not randomly choose every character.
This is why simply counting the visible types of characters is not enough to understand how predictable a password may be.
The method used to create the password also matters.
A Real-Life Example: Creating a New Account
Imagine you are creating a password for an online shopping account.
You create:
Shopping2026!
It contains letters, numbers, and a symbol.
But the password is based on the purpose of the account and a familiar year.
Now imagine a password generator creates:
k7@Q2m#L9
The second password does not use a familiar word or year.
It was created from a defined group of characters.
For entropy calculations, the second situation is easier to describe because the character set and random-generation rules are known.
This is the main reason entropy is often discussed alongside password generation
Entropy and Real Password Guessing
Entropy describes the size of a password space based on a mathematical model.
Real password guessing can involve other information.
For example, attackers may try common:
- words
- names
- dates
- number patterns
- password structures
- previously exposed passwords
Imagine someone creates:
Rahul1998!
The password contains several character types, but its structure is based on a name and a year.
A real guessing attack may take advantage of that kind of predictable construction.
That does not make the entropy formula wrong.
It means the formula is answering a specific question:
How large is the password space when the password is generated according to these rules?
It does not predict exactly how every real password will be guessed.
What Happens When Length and Character Set Both Increase?
Now consider two password settings.
Setting A
8 characters
26 lowercase letters
Possible combinations:
26⁸ = 208,827,064,576
Setting B
12 characters
62 letters and numbers
Possible combinations:
62¹² = 3,226,266,762,397,899,821,056
Setting B has more available characters and more positions.
That makes the possible password space much larger.
This shows why password length and character-set size should be looked at together.
Increasing only one of them changes the result. Increasing both creates an even larger search space.