← Blog

How Long Should a Password Be? Random Password Strength Explained

The short answer: a randomly generated password of 16 characters or more is strong for almost any account, and length matters more than adding symbols. This guide shows where that answer comes from, using the same entropy calculation as Randomify's password strength meter.

What makes a password hard to guess

An attacker who has obtained a scrambled (hashed) copy of a password can test guesses offline, as fast as their hardware allows. What protects you is the number of possible passwords they would have to try.

For a password generated at random, that number is easy to calculate:

possible passwords = (characters available) ^ (length)

Security people express this as entropy bits: the power of two with the same number of possibilities. Every additional bit doubles the work, and the entropy of a random password is:

entropy bits = length × log₂(characters available)

This only applies to passwords chosen at random. A human-chosen password such as Summer2026! uses all four character types, but attackers try words, names, dates, and common substitutions first, so its real strength is far lower than its length suggests.

Exact strength by length and character set

Randomify's character sets contain 26 lowercase letters, 26 uppercase letters, 10 digits, and 26 symbols, so all four sets together give 88 characters.

LengthLowercase only (26)Letters and digits (62)All four sets (88)
837.6 bits47.6 bits51.7 bits
1256.4 bits71.5 bits77.5 bits
1675.2 bits95.3 bits103.4 bits
2094.0 bits119.1 bits129.2 bits

Two things stand out:

  • Length beats variety. A 16-character lowercase password (75.2 bits) is almost as strong as a 12-character password using every character type (77.5 bits), and a 20-character lowercase password (94.0 bits) beats it comfortably.
  • Each extra character helps more than an extra character set. Going from 12 to 16 characters with all four sets adds about 26 bits. Adding symbols to a 16-character letters-and-digits password adds about 8.

The password generator's meter uses these thresholds: below 40 bits is Weak, 40–59 is Fair, 60–79 is Strong, and 80 or more is Very Strong.

What those bits mean in time

Real attack speeds depend on how the website stored the password. A slow, modern password-hashing method can reduce guesses to thousands per second; a fast or outdated one can allow billions. As a deliberately pessimistic illustration, imagine an attacker who can test 100 billion guesses per second:

EntropyTime to try every possibility
40 bitsabout 11 seconds
60 bitsabout 4 months
80 bitsabout 380,000 years
100 bitsabout 400 billion years

On average, an attacker finds the password after trying half the possibilities. Even so, the jump from 60 to 80 bits turns months into geological time. This is why a random 16-character password, at 75 to 103 bits depending on character sets, is a comfortable default.

What current guidance says

The U.S. National Institute of Standards and Technology published its revised digital identity guidelines, NIST SP 800-63B, in August 2025. For organizations that verify passwords, it says:

  • Passwords used on their own must be at least 15 characters long. Passwords used only alongside another factor, such as a code or security key, must be at least 8.
  • Services should allow passwords of at least 64 characters.
  • Services must not impose composition rules, such as requiring a mix of character types, and must not force periodic password changes unless there is evidence of compromise.
  • New passwords must be checked against lists of common and breached passwords.
  • Services must allow password managers and autofill, and should allow pasting.

The guidance is addressed to services rather than individual users, but its direction is clear: long, unique passwords stored in a password manager are better than short, complex passwords that people have to remember.

Practical recommendations

  1. Use a password manager and let it store a different random password for every account. Reusing a password means one breach exposes every account that shares it.
  2. Choose 16 characters or more for generated passwords. Use 20 or more when a site allows it and you never need to type it.
  3. Include all character sets when allowed, but do not worry if a site rejects symbols. Add length instead.
  4. Use "Exclude similar characters" only when you must read or type the password, such as a Wi-Fi password. It removes 0, O, o, l, 1, and I, reducing the pool from 88 to 82 characters, which costs only about 0.1 bit per character.
  5. Turn on two-factor authentication for important accounts. A strong password does not protect you from phishing, but a security key or passkey can.
  6. Remember one strong passphrase, for the password manager itself. Several random words are easier to remember than random characters of equivalent strength.

Generate one now

The random password generator creates passwords from 4 to 64 characters using your browser's cryptographic random generator. The password is generated on your device and shown with its entropy in bits. It is never sent to Randomify's servers or added to a shareable link. Recent results are kept in this browser's history panel until you clear it, so clear the history after use on a shared computer.

For a deeper look at how browsers produce unpredictable values, see how random number generators work.

Frequently asked questions

Is an 8-character password enough? Not on its own. Even with all four character sets, a random 8-character password has about 52 bits of entropy, which a fast offline attack can exhaust in hours. NIST now requires at least 15 characters for passwords used without a second factor.

Are symbols required for a strong password? No. Symbols add strength per character, but length adds more. A 20-character password made only of letters and digits has about 119 bits.

Should I change my passwords regularly? Change a password when there is a reason, such as a breach notification or a suspicion that someone else knows it. Routine forced changes tend to produce weaker, predictable passwords.

Try These Tools