Toolman

32 character password

206.2 bits

32 characters from the full keyboard · about 16 diceware words · Arbitrary.

Arbitrary.

Thirty-two characters is used where a system generates and stores the value itself — API keys, service credentials — and nobody has to type it. As a human password it is theatre.

How long it survives

There is no single answer, and the spread is the point: the same password falls in longer than the universe has existed, by a wide margin or holds for longer than the universe has existed, by a wide margin depending entirely on how the site stored it — which is not something you control.

AttackGuesses per secondTime
Online, rate limited
Guessing against a live login that allows a hundred attempts a second — generous for a real service.
1×10^2longer than the universe has existed, by a wide margin
Offline, slow hash
A stolen database hashed with bcrypt or Argon2 at sensible parameters.
1×10^4longer than the universe has existed, by a wide margin
Offline, fast hash
A stolen database hashed with unsalted SHA-256 or MD5, attacked on GPUs. This is the case worth designing for.
1×10^12longer than the universe has existed, by a wide margin

Assuming half the keyspace on average, and that every character was chosen at random. A password you thought of yourself is worth a fraction of this.

Entropy by character set

Length is only half of it. What matters is length × the bits each character carries, and that depends on how many characters were possible.

Character setBits each32 charactersFast offline attack
lowercase only (26)4.70150.4 bitslonger than the universe has existed, by a wide margin
letters and digits (62)5.95190.5 bitslonger than the universe has existed, by a wide margin
full keyboard (87)6.44206.2 bitslonger than the universe has existed, by a wide margin

Or use words instead

This password is worth about 16 words from a diceware list. The equivalence is close enough to be worth memorising: two random characters ≈ one random word (12.89 bits against 12.92). A passphrase of the same strength is longer to write and far easier to type on a phone, which is the trade.

Nearby lengths

LengthEntropyFast offline attackVerdict
32206.2 bitslonger than the universe has existed, by a wide marginArbitrary.

Frequently asked questions

Is a 32 character password strong enough?

Arbitrary. Thirty-two characters is used where a system generates and stores the value itself — API keys, service credentials — and nobody has to type it. As a human password it is theatre.

How long does it take to crack a 32 character password?

It depends entirely on how it is stored. Against a fast unsalted hash on GPUs, longer than the universe has existed, by a wide margin. Against bcrypt, longer than the universe has existed, by a wide margin. Against a rate-limited login, longer than the universe has existed, by a wide margin. A single "time to crack" figure without that context is meaningless.

How many bits of entropy is a 32 character password?

206.2 bits if every character is chosen at random from the full keyboard — 26 lowercase, 26 uppercase, 10 digits and 25 symbols, which is 6.443 bits each. A password you invented yourself carries far less, because people do not choose randomly.

Is a 32 character password the same as a passphrase?

A 32-character random password is worth about 16 diceware words. Two random characters carry the same entropy as one word from a 7,776-word list — 12.89 bits against 12.92 — so the two approaches are interchangeable at equal strength, and the passphrase is easier to type.

Generate a 32 character password · All lengths compared