The Mathematical Definition of Password Entropy

Password entropy is a measurement of unpredictability borrowed from Claude Shannon's Information Theory. It calculates the logarithm of all possible combinations given the length of the string ($L$) and the character pool size ($R$):

Entropy (Bits) = Length × log2(Pool Size)

Every bit of entropy doubles the time required for a brute-force attacker to guess the credential. For instance, an 8-character lowercase password provides approximately 37.6 bits of entropy, which modern GPU clusters can exhaust in less than 2 minutes. In contrast, a 20-character passphrase generates over 90 bits of entropy, requiring billions of years to compute.