Password Entropy: Understanding the Math Behind It

Password entropy is a way to measure how many different password combinations are possible under a specific set of rules. It is usually expressed in bits.

Two things have the biggest effect on the number of possible passwords:

  • The number of characters you can use
  • The number of characters in the password

For example, a short PIN that uses only numbers has fewer possible combinations than a longer password that can use letters, numbers, and symbols.

The math behind password entropy becomes much easier when you start with a simple example.

How Password Combinations Are Calculated

Imagine a 4-digit PIN.

Each position can contain any number from 0 to 9. That gives you 10 choices for every position.

For four positions:

10 × 10 × 10 × 10 = 10,000

You can also write this as:

10⁴ = 10,000

So there are 10,000 possible four-digit PINs, from 0000 to 9999.

The same idea works for passwords.

The general formula is:

Possible combinations = Nᴸ

Here:

  • N = number of characters available
  • L = password length

For example, suppose a password can use 62 different characters and has 8 characters.

The calculation is:

62⁸ = 218,340,105,584,896

That means the rules allow more than 218 trillion different 8-character strings.

What Do N and L Mean?

The formula uses two simple values.

N: Number of Available Characters

N tells you how many different characters can be used in each position.

For example:

Lowercase letters: 26

Uppercase letters: 26

Numbers: 10

If all three are allowed:

26 + 26 + 10 = 62

So the character set contains 62 possible characters.

If symbols are added, the number of available characters becomes larger.

L: Password Length

L tells you how many characters the password contains.

For example:

6 characters → L = 6

8 characters → L = 8

12 characters → L = 12

So an 8-character password using 62 possible characters has:

N = 62

L = 8

That gives:

62⁸

possible combinations.

The Password Entropy Formula

For a password where each character is chosen independently and uniformly at random from the available character set, entropy can be calculated with:

H = L × log₂(N)

Here:

  • H = entropy in bits
  • L = password length
  • N = number of available characters

You may notice that this formula looks more complicated than Nᴸ.

They are connected.

The first formula:

Nᴸ

tells you how many different passwords are possible.

The entropy formula:

H = L × log₂(N)

expresses the size of that same password space in bits.

So entropy is simply another way of describing the number of possible combinations.

Why Is Entropy Measured in Bits?

Bits are useful for describing very large numbers in a smaller form.

For example:

1 bit = 2 possible outcomes

because:

2¹ = 2

And:

2 bits = 4 possible outcomes

because:

2² = 4

And:

3 bits = 8 possible outcomes

because:

2³ = 8

The same idea works with passwords.

If a password space contains:

2²⁰ = 1,048,576

possible combinations, it can be described as:

20 bits

So when you see an entropy value in bits, it is simply another way of describing how large the possible password space is.

A Simple Four-Digit PIN Example

A four-digit PIN is a good way to understand the complete calculation.

There are:

10 possible digits

and:

4 positions

So:

10⁴ = 10,000 possible PINs

Now calculate the entropy:

H = 4 × log₂(10)

The result is approximately:

13.3 bits

The value 13.3 bits does not mean the PIN has 13.3 characters.

It means the 10,000 possible PINs can be represented as about 13.3 bits.

This is simply a different way of describing the same set of possibilities.

How Password Length Changes the Number of Possibilities

Now move from a PIN to a password.

Suppose a password generator allows 62 characters:

26 lowercase letters + 26 uppercase letters + 10 numbers

Keep this character set the same and change only the password length.

Password LengthPossible CombinationsApprox. Entropy
6 characters62⁶ = 56,800,235,58435.7 bits
8 characters62⁸ = 218,340,105,584,89647.6 bits
10 characters62¹⁰ = 839,808,609,443,436,09659.5 bits
12 characters62¹² = 3,226,266,762,397,899,821,05671.5 bits

The character set stays the same in every example.

Only the password length changes.

The number of possible passwords still grows very quickly.

For example, an 8-character password has:

62⁸

possible combinations.

Adding one more character gives:

62⁹

That new position can contain any of the 62 characters, so the previous number of combinations is multiplied by 62.

This is why adding password length has such a large effect.

How a Larger Character Set Changes the Result

Password length is only one part of the calculation.

The number of available characters also matters.

Suppose the password is 8 characters long in both cases.

Lowercase letters only

There are:

26 possible characters

So:

26⁸ = 208,827,064,576

Lowercase letters + uppercase letters + numbers

There are:

62 possible characters

So:

62⁸ = 218,340,105,584,896

Both passwords have the same length.

The difference is that the second password has more characters available for each position.

The entropy changes as well:

8 × log₂(26) ≈ 37.6 bits

8 × log₂(62) ≈ 47.6 bits

So adding more character choices increases the possible password space.

A Complete Password Entropy Example

Suppose a password generator allows:

26 lowercase letters

26 uppercase letters

10 numbers

That gives:

N = 62

Now set the password length to:

L = 12

First calculate the number of possible passwords:

62¹² = 3,226,266,762,397,899,821,056

Now calculate entropy:

H = 12 × log₂(62)

The result is approximately:

71.5 bits

So the password-generation rules create a very large possible password space.

The important part is understanding where that number comes from:

62 possible characters

combined with:

12 positions

Each position can use any of the 62 characters.

That is what creates the large number of possible combinations.

Why Randomness Matters

This is an important part of password entropy.

The formula assumes that the password characters are chosen randomly from the available character set.

Consider:

Summer2026!

The password contains letters, numbers, and a symbol.

But the way it was created is easy to describe:

Summer + 2026 + !

The person chose a familiar word, added a year, and then added a symbol.

Now compare that with:

q7M@2vL9#

This second example does not follow the same obvious pattern.

The difference is important because entropy calculations work best when the password is genuinely generated from the available character set rather than built around familiar information.

Why Character Variety Alone Is Not Enough

Using several character types does not automatically make a password random.

For example:

Welcome123!

contains:

  • uppercase letters
  • lowercase letters
  • numbers
  • a symbol

Even so, the password follows a familiar pattern:

common word + number + symbol

The character set may look large, but the person did not randomly choose every character.

This is why simply counting the visible types of characters is not enough to understand how predictable a password may be.

The method used to create the password also matters.

A Real-Life Example: Creating a New Account

Imagine you are creating a password for an online shopping account.

You create:

Shopping2026!

It contains letters, numbers, and a symbol.

But the password is based on the purpose of the account and a familiar year.

Now imagine a password generator creates:

k7@Q2m#L9

The second password does not use a familiar word or year.

It was created from a defined group of characters.

For entropy calculations, the second situation is easier to describe because the character set and random-generation rules are known.

This is the main reason entropy is often discussed alongside password generation

Entropy and Real Password Guessing

Entropy describes the size of a password space based on a mathematical model.

Real password guessing can involve other information.

For example, attackers may try common:

  • words
  • names
  • dates
  • number patterns
  • password structures
  • previously exposed passwords

Imagine someone creates:

Rahul1998!

The password contains several character types, but its structure is based on a name and a year.

A real guessing attack may take advantage of that kind of predictable construction.

That does not make the entropy formula wrong.

It means the formula is answering a specific question:

How large is the password space when the password is generated according to these rules?

It does not predict exactly how every real password will be guessed.

What Happens When Length and Character Set Both Increase?

Now consider two password settings.

Setting A

8 characters

26 lowercase letters

Possible combinations:

26⁸ = 208,827,064,576

Setting B

12 characters

62 letters and numbers

Possible combinations:

62¹² = 3,226,266,762,397,899,821,056

Setting B has more available characters and more positions.

That makes the possible password space much larger.

This shows why password length and character-set size should be looked at together.

Increasing only one of them changes the result. Increasing both creates an even larger search space.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top