← Entropy Atlas

Secret & unpredictable

Generated passwords & passphrases

Entropy comes from the selection process, not from how complicated the result looks.

Evaluation card

What “plenty” means here.

Required property
Uniform independent choices from a known list or alphabet, sized for the attacker’s guessing budget.
If it fails
Human preferences, template rules, and reused phrases shrink the real candidate set.
Relevant attacker
An offline cracker with a stolen password verifier, or a rate-limited online guesser.
The Plenty Line
Use a password manager or fair dice method, then size the result for the actual online or offline threat.
Why more is not automatically better
Unusable length can cause reuse or unsafe storage; strong unique credentials plus MFA may be the better margin.

Where it appears

Recognize the pattern.

  • 01password-manager passwords
  • 02dice-generated passphrases
  • 03initial device credentials

The Plentropy rule

Protect the requirement, then stop.

Use a password manager or fair dice method, then size the result for the actual online or offline threat.
Once that claim has comfortable evidence and margin, improve the next limiting factor instead of worshipping a larger entropy number.