Follow your curiosity

What discovery has been shared with you?

Start with one fact. Explore it, go deeper, then follow whichever branch catches your imagination.

Choose subjects for a surprise

Exploring any topic

Begin your discovery

Your next discovery is one click away.

Choose one or more subjects above, or leave Any Topic selected and let curiosity decide.

Mathematics

Understanding Password Strength: Combinations, Character Set, and Length

Quick fact

The number of possible passwords grows exponentially with length, but only polynomially with the size of the character set. Adding one more character to a password often multiplies the number of possible combinations by the size of the character set (e.g., 94), whereas adding a new type of character might only add a few options per position.

Why this is interesting

Ever wondered why changing your password from 'password' to 'P@ssw0rd' feels secure but isn't as strong as you think? The real secret isn't just adding symbols—it's about length.

Read the full explanation

Understanding Understanding Password Strength: Combinations, Character Set, and Length

To understand password strength, think of each character in a password as a slot. For each slot, you can choose one character from a set of allowed characters. The total number of different passwords you can create is the product of the choices for each slot. For example, if you have a 4-character password using only lowercase letters (26 options), there are 26 × 26 × 26 × 26 = 26^4 = 456,976 possibilities. If you add digits (10 more options, giving a character set of 36), the number becomes 36^4 = 1,679,616. But if you keep the character set at 26 and add one more character (making the length 5), you get 26^5 = 11,881,376—far more. The key is that length multiplies the number of possibilities by the size of the character set each time, while adding a new character type only increases the base of the exponent slightly.

A deeper explanation

The underlying principle is the multiplication principle: for a sequence of independent choices, the total number of outcomes is the product of the number of options for each choice. Here, each character position is an independent choice, and the number of options is the size of the character set, denoted as N. For a password of length L, the total number of possible passwords is N^L. This formula shows that increasing L (length) multiplies the total by N, while increasing N (character set size) multiplies the total by a factor that is itself an exponential function of L. In information-theoretic terms, password strength is often measured in 'entropy' bits, computed as L × log2(N). Each bit doubles the number of guesses an attacker must try. Because log2(N) grows slowly as N increases (e.g., log2(26) ≈ 4.7, log2(94) ≈ 6.55), while L multiplies directly, length is generally more effective at increasing entropy than expanding the character set. This is why security experts often recommend longer passphrases over adding special characters. Understanding this mechanism lets you evaluate real-world password policies and understand why a 12-character password with lowercase only (26^12 ≈ 9.5 × 10^16) is much stronger than an 8-character one with everything (94^8 ≈ 6.1 × 10^15).

Keep FACTREE close

Internet access is required. Updates arrive when you reopen or reload the app. You may need to sign in again in the installed app.