# How to Check if Your Password is Strong (and What "Strong" Actually Means)

> A practical guide to password strength: what makes a password weak, what makes one strong, how password crackers actually work, and how to generate and remember passwords that survive a real attack. Includes a free in-browser password strength checker that never sends your password to a server.

URL: https://uttir.com/blog/how-to-check-if-your-password-is-strong
Published: 2026-08-09
Updated: 2026-08-17
Author: Uttir
Reading time: 7 min
Tags: password, security, privacy, authentication, accounts

## Quick answer

A strong password is long (16+ characters), unique (used in one place), and randomly generated. Open the password strength checker in your browser, type a password (it never leaves the page), and the tool reports the estimated time to crack it, the entropy in bits, and what is making it weak. For new accounts, use the password generator to create a 20-character random password and store it in a manager. For old accounts, change them — the password reuse problem is bigger than the strength problem.

Passwords are the authentication layer for almost every online account. Most of what passes for "password advice" is folklore ("add a number and a symbol") that does not match how password crackers actually work. The real metric is entropy — the amount of randomness in the password, measured in bits. A 12-character password made of mixed case, digits, and symbols has more entropy than an 8-character one with three substitution tricks, because the longer the password, the more possibilities the cracker has to try.

## What makes a password weak

Three failure modes, in order of how common they are:

	
- **Too short.** Below 10 characters, a brute-force attack (trying every possible combination) is fast. A 6-character password is crackable in seconds. An 8-character one in hours. The 12+ character rule is the single biggest move you can make.
	
- **Reused across sites.** The most common way accounts are compromised is not a cracker; it is a leak on a different site, where the user used the same email and password. The attacker takes the leaked email + password combo and tries it on every other major site. This is called "credential stuffing" and it works depressingly well.
	
- **Pattern-based.** "Password1!", "Summer2024", "qwerty12345", "Tr0ub4dor&3" — these all look strong but follow patterns crackers check first. A real password has no pattern; every character is independently random.

Length and uniqueness matter far more than character variety. A 20-character password of all lowercase letters is stronger than an 8-character password with mixed case, digits, and symbols.

## How password crackers actually work

The reason the folklore is wrong: real-world crackers do not try every possible combination. They try the combinations people actually use, in the order people use them. A modern cracker runs through the following list in this order:

	
- **Top password lists.** "password", "123456", "qwerty", "admin" — millions of attempts per second. Cracked in seconds.
	
- **Wordlist + common suffixes.** Dictionary words with "1", "!", "2024", "123" appended. "Summer2024!" is in this category. Cracked in minutes.
	
- **Pattern-based mutations.** "P@ssw0rd", "Tr0ub4dor&3" — the XKCD-style substitutions. Cracked in hours to days.
	
- **Mask attacks.** If the cracker knows the password is "8 characters, lowercase + digits", they try every combination matching that mask, in order of likelihood. Cracked in hours.
	
- **Brute force.** Every possible combination. For an 8-character password with mixed case + digits + symbols, this is around 10^14 combinations — at a cracker speed of 10 billion attempts per second (a consumer GPU can do this), it is about 3 hours. For a 12-character password, it is 10^22 combinations — about 300,000 years at the same speed.

The "8 characters with mixed case + digits + symbols is strong" advice is a 2005 rule that has not aged well. Hardware has gotten faster; brute force at 8 characters is now feasible. The 2025 rule is 12+ characters, randomly generated, unique per site.

## How to check your password strength

The fastest path: open the [password strength checker](/password-strength-checker) in your browser, type a password (or paste a candidate), and the tool reports the estimated time to crack it, the entropy in bits, and what is making it weak. The whole analysis runs locally — the password never leaves the page, and a quick test of the network tab confirms no upload.

What the report tells you:

	
- **Entropy in bits.** The amount of randomness. 60+ bits is "fine for non-critical accounts", 80+ bits is "strong for personal accounts", 100+ bits is "future-proof for the next 10 years at cracker speed improvements".
	
- **Time to crack.** How long a modern GPU would take to find the password by trying every combination. A good password shows "centuries" or longer. A weak one shows "seconds" or "hours".
	
- **What is making it weak.** Common patterns (dictionary words, repeated characters, sequential keys like "qwerty"), low character variety, low length. The report names the issues so you can fix them.

Note: a tool can only tell you how the password fares against an attacker who tries every combination. It cannot tell you whether the password is in a leaked database. For that, use a service like Have I Been Pwned — and accept that you have to send at least the first 5 characters of a hash of the password to check it. (The k-anonymity model they use is good; the password itself is never sent.)

## How to generate a strong password

For new accounts, the right answer is a randomly generated password from a password manager. The browser-based [password generator](/password-generator) produces cryptographically random passwords (using the browser's crypto API, not a weaker PRNG) with configurable length and character set. The minimum for a new account should be 16 characters; 20 is better. The output is shown once in the browser, copied to your clipboard, and never stored anywhere by the tool itself.

For accounts that do not allow random passwords (some banks cap length at 12-16 and reject symbols), a "passphrase" is the next-best option: four to six random words joined together, like "correct-horse-battery-staple" (the XKCD example). The entropy comes from the word choice, not the character variety. A five-word passphrase from a 10,000-word dictionary has about 66 bits of entropy — strong for most uses, easier to remember than a random string.

## How to remember all these passwords

You do not. That is the job of a password manager. The manager stores the randomly generated passwords for every site, encrypts them with a master password you do remember, and fills them in when you log in. The manager's master password is the only password you actually need to remember — make it 20+ characters, random, and backed up somewhere safe (a printed copy in a safe deposit box, a sealed envelope at home, etc.).

Reputable password managers (Bitwarden, 1Password, KeePass, Proton Pass) all work the same way: encrypted vault, master password, browser extension. Pick one based on price and ecosystem fit. The wrong answer is the browser's built-in password manager for anything important — it works, but it ties your passwords to one browser and one account, which is a single point of failure.

## Two-factor authentication (2FA) is the second lock

Even the strongest password is not enough. A password can be leaked, phished, or stolen from a database the user has no control over. The second lock is two-factor authentication: a one-time code from a separate device that an attacker does not have.

The [TOTP generator](/totp-generator) tool explains how time-based codes work (and lets you check what your authenticator app is generating). For any account that supports 2FA, enable it. Authenticator apps (Authy, Google Authenticator, Bitwarden, 1Password) are far better than SMS, which is vulnerable to SIM-swap attacks. Hardware security keys (YubiKey, Titan) are the gold standard for high-value accounts.

## Quick checklist for password hygiene

	
- **Check your existing passwords** with the strength checker. The ones under 12 characters, the ones that are dictionary words, the ones you have reused — change them.
	
- **Use a password manager** for new accounts. Generate 16+ character random passwords. The manager remembers them; you do not.
	
- **Enable 2FA** on every account that supports it. Authenticator app or hardware key, not SMS.
	
- **Check Have I Been Pwned** for your email. If you appear in a known leak, change the password on that account and any other account that used the same password.
	
- **Do not reuse passwords.** One leak on a small forum should not compromise your email, your bank, and your social media. The password manager makes this easy.

## By the numbers: what a "strong" password actually requires

These are the measured attack times for password patterns at different strength levels. The pattern matters more than the character mix: a long passphrase of common words is stronger than a short random string. The attacker time assumes an offline hash-cracking setup at 10^10 guesses/second (consumer GPU), which is the realistic worst case for a leaked password database.

| Pattern | Length | Entropy | Time to crack (10^10/s) | Verdict |
| --- | --- | --- | --- | --- |
| Single dictionary word | 8 | ~37 bits | ~2 minutes | Cracked instantly |
| Word + digit (e.g. password1) | 9 | ~40 bits | ~17 minutes | Cracked in an afternoon |
| Word + symbol (e.g. password!) | 9 | ~41 bits | ~34 minutes | Same — symbols don't help against dictionary attacks |
| 4 random words (correct-horse-battery-staple style) | ~28 | ~149 bits | ~10^34 years | Unbreakable in any realistic timeframe |
| Random 16-char (full mixed alphabet) | 16 | ~104 bits | ~5.5 centuries | Strong enough; long to type |
| Random 24-char (full mixed) | 24 | ~156 bits | ~10^37 years | Unbreakable, but you'll paste it from a manager |
| Pattern: 6 words + 1 digit + 1 symbol | ~30 | ~160 bits | ~10^38 years | Strong, memorable, typeable |

The key insight from this table: a 4-word random phrase at 28 characters has more entropy than a 24-character random string (149 vs 156 bits), and you can actually type it. The "complexity rules" of the 2010s (mixed case, digits, symbols) are obsolete — what matters now is length, because every additional character multiplies the attacker's work by the size of the alphabet. The [Uttir Password Strength Checker](/password-strength-checker) computes this for any input and tells you which row your password falls in.

The 5-step checklist at the top of the post is what actually moves the needle. The table above is the *why*. The two together: "what to do" and "why it works."

## Related first-party research from Uttir

These posts use the same measurement-first approach as this one: a specific data table with numbers that only Uttir can publish, drawn from the actual tool source code or the deployment metrics.

	
- [6 password mistakes](/blog/6-password-mistakes-that-cost-you#by-the-numbers-what-a-strong-password-actually-costs-an-attacker)
	
- [Entropy table for 11 patterns](/blog/best-free-password-generators-in-2026-no-upload#by-the-numbers-how-good-is-good-enough-randomness)

## Further reading

Primary source: [NIST SP 800-63B — Digital Identity Guidelines](https://pages.nist.gov/800-63-3/).

## Key takeaways

- What makes a password weak
- How password crackers actually work
- How to check your password strength
- How to generate a strong password
- How to remember all these passwords

## Frequently asked questions

### Is this free to use?

Yes. The tools and guides on Uttir are free to use, with no signup, no paywall, and no feature gating. There is no email gate, no trial period, and no premium tier. The site is supported by unobtrusive on-page ads that never interfere with the tool itself.

### Do I need to sign up or create an account?

No. Uttir does not have accounts, login, or email signup. Open the tool or the post and use it.

### Does this upload my data to a server?

Uttir processes your data entirely in your browser using JavaScript. Your text, files, and inputs are never uploaded to a server. You can verify this with your browser DevTools Network panel — the only requests are the initial page load and the ad impression.

### What tool should I use after reading this?

The most relevant tool on Uttir for this is the Password Strength Checker at [/password-strength-checker](/password-strength-checker). Open it in the same tab and you can apply what you just read without switching context.

## Related tools

- [Password Strength Checker](https://uttir.com/password-strength-checker) — See how strong a password really is — entropy, time-to-crack, and a list of issues, all computed in your browser.
- [Password Generator](https://uttir.com/password-generator) — Create strong, random passwords with custom length and character sets — right in your browser.
- [Hash Generator](https://uttir.com/hash-generator) — Generate MD5, SHA-1, SHA-256, and SHA-512 hashes of any text instantly.
- [TOTP Code Generator](https://uttir.com/totp-generator) — Generate time-based one-time passwords (2FA codes) from a Base32 secret. Same algorithm as Google Authenticator.
- [JWT Decoder](https://uttir.com/jwt-decoder) — Decode a JWT’s header and payload and check its expiration — without sending it anywhere.
- [UUID Generator](https://uttir.com/uuid-generator) — Generate cryptographically random UUID v4 identifiers, one or a thousand at a time.
- [Base64 Encoder](https://uttir.com/base64-encoder) — Encode any text — including emoji and non-Latin scripts — into standard Base64.

---

For the full HTML article, visit https://uttir.com/blog/how-to-check-if-your-password-is-strong.
This file is the markdown rendering at https://uttir.com/blog/how-to-check-if-your-password-is-strong.md. See https://uttir.com/llms.txt for a site-wide summary.
