Force des mots de passe et entropie : Guide complet de sécurité
Calculez l'entropie selon la théorie de Shannon, évaluez les vitesses réelles de brute-force GPU et comprenez la supériorité de la longueur sur la complexité.
Points clés
- L'entropie se calcule en bits : H = L × log2(R) où L est la longueur et R la taille de l'ensemble des caractères.
- Une phrase secrète de 16 caractères offre plus de 80 bits d'entropie et résiste aux fermes de GPU modernes.
- La longueur augmente la résistance de manière exponentielle, tandis que les caractères spéciaux n'ajoutent qu'un gain linéaire.
- Évitez les vérificateurs en ligne non sécurisés ; privilégiez toujours le calcul local via Web Crypto.
Tester l'entropie de votre mot de passe localement
Calculez l'entropie en bits, estimez le temps de craquage GPU et générez des phrases secrètes sans envoi sur serveur.
- 100% Client-side execution
- Shannon bit entropy score
- Online & offline cracking times
- Web Crypto secure generator
01.The Mathematics of Password Entropy (Shannon Information Theory)
// Shannon Entropy Calculation in TypeScript
function calculatePasswordEntropy(password: string): number {
let poolSize = 0;
if (/[a-z]/.test(password)) poolSize += 26;
if (/[A-Z]/.test(password)) poolSize += 26;
if (/[0-9]/.test(password)) poolSize += 10;
if (/[^a-zA-Z0-9]/.test(password)) poolSize += 33; // Standard printable symbols
if (poolSize === 0 || password.length === 0) return 0;
return Math.round(password.length * Math.log2(poolSize));
}02.GPU Clusters & Modern Brute-Force Cracking Times
03.Why Length Beats Complexity: The XKCD Passphrase Model
04.Why Local In-Browser Calculation is Essential for Credential Security
Local Browser Evaluation vs. Remote Cloud Checkers
Technical architectural comparison between local browser execution and cloud server processing.
| Security Feature | Local Webiodd Tool | Traditional Cloud Checkers |
|---|---|---|
| Credential Data Transmission | 0 Bytes (100% In-Browser Memory) | Transmitted over HTTP/HTTPS POST |
| Server Log Retention | Impossible (Zero Server Interaction) | Vulnerable to Access Logs & Telemetry |
| Evaluation Latency | Sub-millisecond (Instant Keystroke UI) | 150ms - 800ms Network Roundtrip |
| Offline Availability | Fully Functional Without Internet | Fails When Disconnected |
| RNG Security Level | CSPRNG (crypto.getRandomValues) | Variable / Unverifiable Pseudo-RNG |
How to Evaluate and Generate Secure Passwords
Follow these step-by-step instructions to test your password entropy and generate ultra-secure credentials.
Open the Analyzer
Navigate to the Password Strength & Entropy tool in your browser.
Enter Your Password or Phrase
Type or paste your candidate password into the real-time evaluation field.
Analyze Entropy & Crack Times
Examine the Shannon entropy bit score, pool size calculation, and cracking time breakdown across online and offline attack scenarios.
Generate High-Entropy Credentials
Use the integrated Web Crypto generator to create 24+ character random strings or multi-word passphrases with a single click.
Password Security Best Practices & Guidelines
- ✓Aim for a minimum of 75 bits of entropy for general accounts, and 90+ bits for master passwords and root credentials.
- ✓Adopt random multi-word passphrases (5+ words) for secrets you need to remember by heart.
- ✓Always utilize an encrypted, zero-knowledge password manager with hardware security keys (FIDO2/WebAuthn).
- ✓Never reuse passwords across different services; a single breach compromises all matching accounts.