← Entropy Atlas
Secret & unpredictable
Generated passwords & passphrases
Entropy comes from the selection process, not from how complicated the result looks.
Evaluation card
What “plenty” means here.
- Required property
- Uniform independent choices from a known list or alphabet, sized for the attacker’s guessing budget.
- If it fails
- Human preferences, template rules, and reused phrases shrink the real candidate set.
- Relevant attacker
- An offline cracker with a stolen password verifier, or a rate-limited online guesser.
- The Plenty Line
- Use a password manager or fair dice method, then size the result for the actual online or offline threat.
- Why more is not automatically better
- Unusable length can cause reuse or unsafe storage; strong unique credentials plus MFA may be the better margin.
Where it appears
Recognize the pattern.
- 01password-manager passwords
- 02dice-generated passphrases
- 03initial device credentials
The Plentropy rule
Protect the requirement, then stop.
Use a password manager or fair dice method, then size the result for the actual online or offline threat.
Once that claim has comfortable evidence and margin, improve the next limiting factor instead of worshipping a larger entropy number.