Text & everyday tools · Password Generator
How to calculate passphrase entropy: words, wordlist size and log2
· How it works
passwords passphrases entropy
A hands-on guide to the one formula that matters — words × log2(wordlist size) — with comparisons to random-character passwords, so you can set a word count with reasons rather than habit.
How many words is enough? — why the question has an arithmetic answer rather than a feeling
ToolAcre allows three through sixteen passphrase words, but the repository does not declare one count sufficient for every account or attacker. “Enough” depends on a threat model beyond a generator’s source. What the code can answer exactly is how many choices its own process makes after the selected wordlist has been filtered by the minimum and maximum word lengths.
That narrower question is still useful. It lets a reviewer compare settings without pretending the result covers phishing, reuse or device compromise. Start with the actual eligible pool returned by `generateWordlist`, not the advertised unfiltered list size, because excluding words changes the number of possible outcomes available to each draw.
How many words the shipped settings allow, and what can be calculated from that
If one draw chooses uniformly from N eligible words, its contribution is log₂(N). With replacement and W independent draws, the word contribution is W × log₂(N). The package entropy function uses the filtered unique wordlist length, and tests confirm that adding one word increases the estimate by log₂ of that same pool.
The formula belongs to the selection process, not to the printed phrase in isolation. A person could type the same sequence after choosing favourite words, producing identical text through a different and unquantified process. ToolAcre therefore estimates settings it controls and does not accept an existing password for scoring.
The EFF numbers — roughly 12.9 bits per word from the long list and roughly 10.3 from the short lists
The committed long file contains exactly 7,776 nonblank entries, while each short file contains 1,296. Build-time tests count the real files and compare them with the option table, so these sizes are verified rather than copied from a label. Their unfiltered per-draw values are log₂(7,776), about 12.9, and log₂(1,296), about 10.3.
A word-length range can reduce either pool. The entropy readout uses the words that actually loaded and survived filtering, preventing a stale label from controlling the calculation. If a range admits zero or one word, validation refuses generation instead of printing a reassuring number for a process with no useful variety.
The verified EFF list sizes: 7,776 and 1,296 entries
Character mode has a parallel calculation from its selected alphabet, but its generation policy also reserves one character from every selected class and then securely shuffles the result. Comparisons should therefore name the exact supported alphabet and length rather than assume “mixed characters” always means the same set. ToolAcre omits quotes, backslash, backtick and space from its symbol pool for handling reliability.
A generated lowercase-only string can be compared arithmetically with generated words because both pools are explicit and draws use the same secure integer primitive. That comparison says nothing about a human-created lowercase password or phrase. Uniform independent choices are the load-bearing assumption, and changing the choice method changes the model.
Comparing generated words and characters only from their verified pool sizes
Suppose the unfiltered long list is selected for six words. The word calculation is 6 × log₂(7,776), approximately 77.5 bits. Seven draws from a 1,296-entry short list yield 7 × log₂(1,296), approximately 72.4 bits. These values follow directly from verified file sizes, but neither is declared a universal target for a laptop, Wi-Fi network or vault.
If the user narrows word lengths, replace 7,776 or 1,296 with the eligible count shown by the current pool. Random case adds one independent upper-or-lower choice per word. A random delimiter selects among five characters for each gap. Fixed capitalization and a fixed separator add no random choice in this implementation.
Worked example: calculate settings, without prescribing one threat-model target
Entropy does not measure whether a credential is reused, typed into a phishing page, captured by malware or exposed through a clipboard manager. It also does not describe how a remote service hashes, rate-limits or recovers accounts. The limitations page explicitly separates generator arithmetic from those risks instead of presenting one number as a complete security score.
Even the displayed search-time prose rests on a stated hypothetical rate. Changing that assumption changes the duration, so the time is a comparison aid rather than a forecast. The reproducible figure is the choice count derived from settings; attack cost requires evidence about systems outside the tab.
What this does not cover — passwords chosen by people, whose entropy cannot be calculated this way
Words chosen by a person do not inherit the list formula merely because every token appears in the EFF file. People favour grammar, themes, quotations and familiar associations, making the distribution unknown. Without a documented random process, assigning W × log₂(N) would describe a generator that was not used.
For that reason ToolAcre generates rather than evaluates. It will not tell someone that a phrase they invented has the same estimate as a uniformly selected one. It also does not recommend publishing generated examples; once a particular result appears in an article, it is no longer a secret candidate.
The takeaway — decide the bits you need, divide by 12.9, round up, then generate a passphrase with the Password Generator and count its words against your target
Use the estimate to reason about controls the page actually exposes: verified list, eligible length range, word count, delimiter rule and case rule. Recalculate whenever those inputs change. The formula is transparent enough to reproduce, and the implementation derives its pool from the loaded data rather than trusting presentation text.
Stop the conclusion at the edge of that model. A higher calculated choice count is not proof against every threat, permission to reuse a credential or a replacement for a manager. It is an honest description of one local random-generation process whose pool sizes and draws can be inspected.