Umbrixon

Free toolkit

Key Gauge

Type a password and watch its real strength appear as you go. Key Gauge estimates the character pool, entropy and how long an offline attacker would need to crack it.

Waiting for input…

Length
0
Character pool
0
Entropy
0 bits
Est. offline crack time
—

    All computation happens locally in JavaScript. Umbrixon never sees what you type here.

    How the estimate works

    Strength here means entropy, the number of equally likely combinations an attacker would have to try. We count the character sets you actually used, multiply out the possibilities across the length, and translate that into a crack time assuming a fast offline attacker making a hundred billion guesses a second. Length moves that number far more than swapping a letter for a symbol, which is why the meter rewards a longer password over a short and cryptic one.

    Then stop reusing it

    A strong password you use in two places is a weak password. Once one site leaks, Key Gauge can't help, but Exposure Scan will tell you which of your logins are already circulating.