How long should a password be? A brute-force time table, and where the math misleads

Published 2026-09-19 · By niherattyo

Is eight characters really too short? Do symbols help more than length? We built a table with the same formula as the site’s strength checker, then tested the passwords that formula cannot see through.

Assumptions

Every number here uses the same formula as this site’s password strength checker.

  • Possibilities per character: the total for the character types used — 10 digits, 26 lowercase, 26 uppercase, 32 symbols
  • Strength (entropy) = length × log₂(possibilities) bits
  • Time to brute-force = 2entropy ÷ guesses per second

We assume 10 billion guesses a second, roughly what powerful hardware manages against a leaked password hash (the scrambled form services store). Times in the tables are for trying every combination; on average a password falls in half that time.

Quick reference: length and character types

Time to brute-force a randomly generated password.

LengthDigits only (10)Lowercase only (26)Letters + digits (62)Letters, digits, symbols (94)
6InstantInstant6 s~1 min
8Instant21 s6 h7 days
101 s4 h2.7 years171 years
122 min110 days10,000 years1.5 million years
142.8 h205 years39 million years13 billion years
1612 days138,000 years151 billion yearsover 100 trillion years
20317 years63 billion yearsover 100 trillion yearsover 100 trillion years

What this shows

  • Length beats variety: 14 lowercase letters (205 years) outlast 10 characters using all four types (171 years). Each extra character multiplies the time by the number of possibilities — 26 for lowercase, 94 for everything.
  • Eight characters falls in a week even with every type: the old “at least 8 characters” advice does not hold up once a hash has leaked.
  • Past 12 characters it becomes impractical: 12 characters of every type take 1.5 million years, and 16 take over 100 trillion.
  • Numeric PINs rely on attempt limits: four digits allow only 10,000 combinations. Short bank-card and phone PINs work because the device locks after a few wrong tries.

Attack speed changes everything

The same password holds out for very different times depending on how fast the attacker can guess.

Attack8 characters (94)12 characters (94)
Through a login page (assumed 1,000/s)190,000 years15 trillion years
Leaked hash, brute force (10 billion/s)7 days1.5 million years
100 times faster (1 trillion/s)1.7 h15,000 years

Guessing through a login page is slow, and most services lock the account after repeated failures. The real danger is a service leaking its password hashes, which attackers can then test as fast as their hardware allows. That is where length makes the difference.

Passwords the formula gets wrong

The tables above assume random passwords. Passwords people make up fall much faster. Running a few through the strength checker exposed its weak spots.

PasswordBeforeAfterComment
P@ssw0rd52.4 bit
7 days
24.0 bit
Instant
Just "password" with look-alike swaps
Password1!65.5 bit
171 years
24.0 bit
Instant
The classic word + digit + symbol shape
Tokyo2020!65.5 bit
171 years
24.0 bit
Instant
Place name + year + symbol
tanaka198551.7 bit
4 days
51.7 bit
4 days
Surname + birth year; the formula cannot tell (see below)
correct horse battery staple164.0 bit
over 100 trillion years
164.0 bit
over 100 trillion years
A string of words; the formula overrates it (see below)
k7#Qm2!xR9vB78.7 bit
1.5 million years
78.7 bit
1.5 million years
An example of 12 random characters; the formula holds

The weakness we found, and the fix

At first the checker rated P@ssw0rd at “7 days” and Password1! at “171 years”. Yet both are classic shapes near the top of leaked-password lists. Before any random brute force, attackers try common words with look-alike swaps (a→@, o→0) and a number or symbol tacked on.

We improved the checker: it now undoes look-alike swaps, strips leading and trailing digits and symbols, and if what remains is a common word it caps the strength at 24 bits (cracked instantly) (19 September 2026). We ran 200,000 random passwords through it to confirm none are flagged by mistake.

What no formula can catch

  • Names, birthdays and phone numbers: tanaka1985 scores “4 days”, but anyone who knows you — or an attacker who gathers your social media details — can guess it far faster. Personal information cannot be judged by a formula.
  • Passphrases of words: correct horse battery staple is long, so the formula calls it extremely strong. But an attacker who knows the shape is “four words” tries combinations of words, not characters. Four words chosen at random from a 2,048-word list give 44 bits, cracked in about 29 minutes at 10 billion guesses a second. If you use a passphrase, choose six words from a 7,776-word list with dice (Diceware): about 77.5 bits, or roughly 700,000 years.

The site’s password generator uses 18 symbols, while the strength checker counts symbols as 32, so it rates generated passwords slightly higher than they are. For example, 12 characters of letters, digits and symbols from the generator are really about 75.9 bits (about 220,000 years).

Summary

  • Passwords you do not need to remember: generate 16 or more random characters with the password generator and keep them in a password manager.
  • Passwords you must remember: use a passphrase of six or more randomly chosen words. Avoid sentences you made up and letter swaps.
  • Never reuse passwords: however strong, a password leaked from another service will be tried as is.
  • Turn on two-factor authentication: even if your password becomes known, it is not enough on its own to log in.

Tools used in this article