
A/B Testing Password Strength (Per-User) Calculator FAQ
Answers to common questions about password entropy, per-user compromise estimates, attack assumptions, and password policy comparisons.
This FAQ explains what the calculator estimates, how to choose inputs, and why real-world account security can differ from a simplified password-guessing model.
General calculator questions
Basics of comparing two password policies under one attack scenario.
What does this password strength A/B calculator compare?
It compares policy A and policy B by estimating per-targeted-user compromise likelihood and expected affected accounts under identical attack assumptions.
What is a per-user compromise likelihood?
It is the modelled chance that one targeted account is compromised during the specified attack window.
What does “expected compromised accounts” mean?
It is the targeted account count multiplied by the estimated per-user likelihood. It is an expected value, not a guaranteed count.
Why must both policies use the same attack scenario?
Holding guess rate, duration, and account coverage constant isolates the estimated effect of the password policy difference.
Entropy and calculation questions
How entropy and attacker guesses are translated into the model outputs.
What is password entropy measured in bits?
It is a way to express the effective size and unpredictability of a password search space. More bits generally mean more guesses are required.
How are average guesses estimated?
The calculator uses 2^(entropy bits − 1), which represents half of the effective search space as a simplified average search effort.
Why does a small entropy increase produce a large change?
Entropy is exponential: each additional bit doubles the search space, so several added bits can materially reduce the estimate.
Can the calculator show more than 100% risk?
No. The probability is capped at 100% because a likelihood cannot exceed certainty.
Choosing inputs
Guidance for setting scenario inputs without treating estimates as fixed facts.
How should I choose attack guesses per second?
Use a scenario-specific estimate. Online attacks may be constrained by rate limits, while offline attempts depend heavily on password hashing and attacker capability.
What attack duration should I enter?
Enter the period during which an attacker could plausibly continue making guesses in the scenario you are modelling.
What does accounts targeted mean?
It is the percentage of active accounts assumed to be included in the attack. It affects population impact, not the per-user likelihood.
Should I enter the policy minimum entropy?
Use an estimate of actual average effective user password entropy where possible. A policy minimum may not represent real password choices.
Accuracy and security context
Important factors outside the simplified guessing model.
Does this calculator measure total account takeover risk?
No. It focuses on a simplified password-guessing scenario and excludes many other takeover paths.
Does multi-factor authentication affect the result?
It is not included in the formula. Multi-factor authentication can reduce the impact of a guessed password, but implementation and recovery paths also matter.
Does password reuse affect the estimate?
No. Reuse can materially change real-world risk and is outside this entropy-based model.
Does secure password hashing matter?
Yes. Hashing and related storage controls can substantially affect feasible offline guess rates, but their effects must be represented through the guess-rate assumption.
What does this calculator estimate?
It estimates per-targeted-user password compromise likelihood and expected affected accounts for two policies under the same assumed attack scenario.
Explore Related Questions
Ready to see what you can calculate?
Open the calculator and get personalized results in seconds.
