6 character password
38.7 bits
6 characters from the full keyboard · about 3 diceware words · Not usable.
Not usable.
Six characters is 39 bits. Against fast hardware it falls in well under a minute, and it is short enough that a targeted attack will simply enumerate it. There is no context in which this is a reasonable choice today.
How long it survives
There is no single answer, and the spread is the point: the same password falls in instantly or holds for 69 years depending entirely on how the site stored it — which is not something you control.
| Attack | Guesses per second | Time |
|---|---|---|
| Online, rate limited Guessing against a live login that allows a hundred attempts a second — generous for a real service. | 1×10^2 | 69 years |
| Offline, slow hash A stolen database hashed with bcrypt or Argon2 at sensible parameters. | 1×10^4 | 251 days |
| Offline, fast hash A stolen database hashed with unsalted SHA-256 or MD5, attacked on GPUs. This is the case worth designing for. | 1×10^12 | instantly |
Assuming half the keyspace on average, and that every character was chosen at random. A password you thought of yourself is worth a fraction of this.
Entropy by character set
Length is only half of it. What matters is length × the bits each character carries, and that depends on how many characters were possible.
| Character set | Bits each | 6 characters | Fast offline attack |
|---|---|---|---|
| lowercase only (26) | 4.70 | 28.2 bits | instantly |
| letters and digits (62) | 5.95 | 35.7 bits | instantly |
| full keyboard (87) | 6.44 | 38.7 bits | instantly |
What four more characters buy
Entropy is linear in length and the search space is exponential in entropy, so the step is not gentle. Going from 6 to 10 adds 25.8 bits — which multiplies the work by 57,289,761. Four keystrokes you will never type, because a password manager types them.
Or use words instead
This password is worth about 3 words from a diceware list. The equivalence is close enough to be worth memorising: two random characters ≈ one random word (12.89 bits against 12.92). A passphrase of the same strength is longer to write and far easier to type on a phone, which is the trade.
Nearby lengths
| Length | Entropy | Fast offline attack | Verdict |
|---|---|---|---|
| 6 | 38.7 bits | instantly | Not usable. |
| 8 | 51.5 bits | 27 minutes | The old minimum, and no longer enough. |
| 10 | 64.4 bits | 144 days | Borderline. |
Frequently asked questions
Is a 6 character password strong enough?
Not usable. Six characters is 39 bits. Against fast hardware it falls in well under a minute, and it is short enough that a targeted attack will simply enumerate it. There is no context in which this is a reasonable choice today.
How long does it take to crack a 6 character password?
It depends entirely on how it is stored. Against a fast unsalted hash on GPUs, instantly. Against bcrypt, 251 days. Against a rate-limited login, 69 years. A single "time to crack" figure without that context is meaningless.
How many bits of entropy is a 6 character password?
38.7 bits if every character is chosen at random from the full keyboard — 26 lowercase, 26 uppercase, 10 digits and 25 symbols, which is 6.443 bits each. A password you invented yourself carries far less, because people do not choose randomly.
Is a 6 character password the same as a passphrase?
A 6-character random password is worth about 3 diceware words. Two random characters carry the same entropy as one word from a 7,776-word list — 12.89 bits against 12.92 — so the two approaches are interchangeable at equal strength, and the passphrase is easier to type.