WEBioDD Logo
WEBioDD
返回开发者工具
香农熵与暴力破解数学8 分钟阅读最后更新于

密码熵值与强度计算:香农信息论与暴力破解深度解析

基于香农熵公式计算密码强度,剖析现代 GPU 集群破解速度,证明长度比复杂符号具有更高的安全效益。

W
WEBioDD 工程团队•100% 浏览器本地运行 & 零信任

核心要点

  • 熵值以比特计算:H = L × log2(R),其中 L 为长度,R 为字符集基数。
  • 由随机单词组成的16位密码可提供超过80比特的熵,能有效防御现代 GPU 阵列。
  • 密码长度带来指数级安全增长,而添加特殊字符仅产生线性收益。
  • 避免使用发送请求的在线测试工具,始终使用纯客户端 Web Crypto 工具评估。
100% In-Browser & Local Execution

本地测试密码熵值与安全性

计算信息熵比特位,估算 GPU 集群暴力破解耗时,纯离线生成高强度密码。

  • 100% Client-side execution
  • Shannon bit entropy score
  • Online & offline cracking times
  • Web Crypto secure generator

01.The Mathematics of Password Entropy (Shannon Information Theory)

Password entropy is the foundational metric used in cybersecurity to quantify the uncertainty and strength of an authentication secret. Derived from Claude Shannon’s 1948 information theory, bit entropy (H) measures how many binary guesses an adversary would need in the worst-case exhaustive search scenario. The formula is defined as H = L × log2(R), where L represents the length of the string and R denotes the size of the character pool (e.g., 26 for lowercase, 62 for alphanumeric, 95 for full printable ASCII). Each additional bit of entropy doubles the total number of possible combinations, creating an exponential barrier for brute-force attacks.
typescriptClient-side mathematical entropy evaluation algorithm
// Shannon Entropy Calculation in TypeScript
function calculatePasswordEntropy(password: string): number {
  let poolSize = 0;
  if (/[a-z]/.test(password)) poolSize += 26;
  if (/[A-Z]/.test(password)) poolSize += 26;
  if (/[0-9]/.test(password)) poolSize += 10;
  if (/[^a-zA-Z0-9]/.test(password)) poolSize += 33; // Standard printable symbols

  if (poolSize === 0 || password.length === 0) return 0;
  return Math.round(password.length * Math.log2(poolSize));
}

02.GPU Clusters & Modern Brute-Force Cracking Times

Modern password cracking utilizes dedicated multi-GPU rigs (such as 8x NVIDIA RTX 4090 clusters) running tools like Hashcat. An 8-GPU rig can compute over 100 billion NTLM or MD5 hashes per second. For weak 8-character alphanumeric passwords (representing 62^8 ≈ 218 trillion combinations), cracking takes less than 35 minutes on consumer-grade hardware. However, increasing length to 16 characters expands the search space to 62^16 ≈ 4.76 × 10^28 combinations, rendering brute-force attacks impossible within human cosmological timescales regardless of computational power.
Fast hashing algorithms (MD5, SHA-1, SHA-256) without key-stretching salts offer near-zero resistance against GPU arrays. Modern systems must enforce Argon2id or bcrypt.

03.Why Length Beats Complexity: The XKCD Passphrase Model

Traditional password composition rules (requiring uppercase, lowercase, numbers, and symbols) often lead users to predictable substitutions (e.g., replacing "a" with "@" or appending "1!"). These patterns are heavily targeted by rule-based and mask-based cracking dictionaries. In contrast, multi-word passphrases (e.g., "correct-horse-battery-staple") leverage a dictionary pool of 10,000+ common words. A 4-word random passphrase yields (10,000)^4 = 10^16 combinations (~53 bits of pure entropy), while remaining easy for humans to memorize without writing down.

04.Why Local In-Browser Calculation is Essential for Credential Security

Many online password strength meters transmit user input to remote servers for validation. This introduces massive security vulnerabilities: network interception, server access logs recording plaintext secrets, third-party analytics leaks, and compliance violations. A secure password analyzer must execute 100% client-side inside the browser’s JavaScript V8/SpiderMonkey engine, using the window.crypto API for random generation, ensuring not a single byte ever leaves the user device.
Our Password Strength Analyzer executes entirely in your browser memory. Inspect the Network tab in DevTools to confirm zero outgoing HTTP requests.

Local Browser Evaluation vs. Remote Cloud Checkers

Technical architectural comparison between local browser execution and cloud server processing.

Security FeatureLocal Webiodd ToolTraditional Cloud Checkers
Credential Data Transmission0 Bytes (100% In-Browser Memory)Transmitted over HTTP/HTTPS POST
Server Log RetentionImpossible (Zero Server Interaction)Vulnerable to Access Logs & Telemetry
Evaluation LatencySub-millisecond (Instant Keystroke UI)150ms - 800ms Network Roundtrip
Offline AvailabilityFully Functional Without InternetFails When Disconnected
RNG Security LevelCSPRNG (crypto.getRandomValues)Variable / Unverifiable Pseudo-RNG

How to Evaluate and Generate Secure Passwords

Follow these step-by-step instructions to test your password entropy and generate ultra-secure credentials.

1

Open the Analyzer

Navigate to the Password Strength & Entropy tool in your browser.

2

Enter Your Password or Phrase

Type or paste your candidate password into the real-time evaluation field.

3

Analyze Entropy & Crack Times

Examine the Shannon entropy bit score, pool size calculation, and cracking time breakdown across online and offline attack scenarios.

4

Generate High-Entropy Credentials

Use the integrated Web Crypto generator to create 24+ character random strings or multi-word passphrases with a single click.

Password Security Best Practices & Guidelines

  • ✓Aim for a minimum of 75 bits of entropy for general accounts, and 90+ bits for master passwords and root credentials.
  • ✓Adopt random multi-word passphrases (5+ words) for secrets you need to remember by heart.
  • ✓Always utilize an encrypted, zero-knowledge password manager with hardware security keys (FIDO2/WebAuthn).
  • ✓Never reuse passwords across different services; a single breach compromises all matching accounts.

Frequently Asked Questions (FAQ)

An entropy score of 60-79 bits is considered good for standard web accounts. For critical infrastructure, banking, and master passwords, target 80 to 128+ bits of entropy.
开发者指南与技术教程

针对 15 款纯浏览器端开发与诊断工具的架构深度剖析、Web API 解析与零信任本地隐私保护指南。

© 2026 WEBioDD Engineering Network. All technical guides are free and open.

100% Client-Side Privacy Guaranteed