EntropyCalc Pro

Shannon Entropy & Hardware Crack Time Simulator

🔒 100% Client-Side Privacy

Password Entropy & Crack Time

Calculate exact information entropy in Shannon bits, examine theoretical permutations, and estimate brute-force crack time against modern RTX 4090 GPU clusters.

Cybersecurity Tools Compare end-to-end encrypted password managers, hardware security keys (FIDO2 / YubiKey), and secure cloud backups.
Presets:
Lowercase (a-z)
Uppercase (A-Z)
Numbers (0-9)
Symbols (!@#$)

🎲 Random Passphrase Generator

Cryptographically Secure

Generate high-entropy Diceware style passphrases that are easy for humans to memorize but mathematically impossible for computers to brute-force.

Shannon Entropy 72.3 Bits of Entropy
Character Space 95 Symbols in Pool
Password Length 11 Characters
Security Classification Very Strong

Excellent cryptographic resistance. Exhausting this search space requires astronomical computation beyond current and near-future supercomputers.

Hardware Brute Force Crack Times (Fast Hash: MD5 / NTLM)

Assuming offline hash dump analysis with specialized modern cracking hardware.

🌐 Online Web Login (Rate limited, 100/min)
14,200 years
💻 Desktop Multi-Core CPU (100 MH/s)
8.4 years
🎮 1x NVIDIA RTX 4090 (120 GH/s)
2.6 days
🏭 8x RTX 4090 Dedicated Rig (1 TH/s)
7.8 hours
🏢 Government Supercomputer Cluster (100 TH/s)
4.7 minutes

Understanding Cryptographic Entropy & Modern Cracking Hardware

1. The Mathematics of Shannon Entropy

Entropy defines the logarithmic search space of possible combinations:

Permutations P = R^L
Entropy E = L * log₂(R) bits

A password with 64 bits of entropy has 2⁶⁴ (approx. 18.4 quintillion) possible combinations. Under Kerckhoffs's principle, attackers know your length and character set; your sole defense is pure entropy depth.

2. Why Length Beats Complexity (NIST SP 800-63B)

Traditional complexity rules (forcing 1 symbol, 1 uppercase, 1 digit) lead humans to predictable patterns: e.g. Password1!.

NIST guidelines officially recommend longer, multi-word passphrases (e.g. galaxy-orbit-velvet-cobalt). Adding 4 characters increases the search space by a factor of 95⁴ (81 million times larger).

Frequently Asked Questions

How does salting and hashing protect against brute force?

Cryptographic salts prevent attackers from using precomputed rainbow tables. Furthermore, modern key-derivation functions like Argon2id and bcrypt require substantial CPU memory (e.g., 64MB per attempt), preventing GPUs from running billions of parallel guesses per second.

How many bits of entropy are considered safe in 2026?

For online accounts protected by rate limiting and 2FA, 50 to 60 bits is generally secure. For full disk encryption, password manager master keys, or cryptocurrency private keys subject to offline brute-force attacks, a minimum of 80 to 100 bits of entropy is recommended.

What is Diceware?

Diceware is a cryptographic method created by Arnold Reinhold where rolling physical dice selects words from a curated list of 7,776 words. Because each roll yields log₂(7776) = 12.92 bits of entropy, a 5-word Diceware passphrase provides approximately 64.6 bits of true mathematical unpredictability.