How long should a master password be?

How long should a password be? For a master password, aim for 16+ random characters or six random words. Here is why, with honest crack-time estimates.

A capybara proudly holds up a very long, elegant key with many intricate teeth, while a tiny plain key lies forgotten on the floor.
On this page

How long should a password be? For a master password that protects encrypted data, aim for at least 16 characters, and let a generator pick them: six random words, or a random string from a password manager. Length only protects you when every character is hard to predict, so a long password you made up yourself can still fall quickly.

Below: where popular "time to crack" numbers come from, why offline guessing after a data theft is the real danger for an encrypted notes vault, and how much a slow, memory-hungry key derivation changes the math, with Cappa's own settings as the worked example.

How long should a password be? The short answer

The right length depends on how the password is made. A random string from a password manager packs the most unpredictability into each character. Words picked by dice pack less but are easier to type and remember. A phrase you invent yourself is the weakest, because people choose in predictable ways.

How the password is madeGood target for a master passwordUnpredictability (bits)
Random characters from a password manager (letters, digits, symbols)16 characters or moreabout 105 bits at 16 characters
Random letters and digits only16 to 20 charactersabout 95 bits at 16 characters
Random words from the 7,776-word EFF list6 words (5 at minimum)about 77.5 bits for 6 words
A sentence you made up yourselfHard to estimate; treat it as much weaker than it looksunknown
Bits of entropy
A measure of how many equally likely possibilities an attacker has to search. Each extra bit doubles the work. A password with 60 bits has 2^60 (about a billion billion) equally likely options, and on average an attacker finds it after searching half of them.

Bits only make sense for passwords chosen at random. Keep that in mind when reading any crack-time table.

What crack-time tables actually measure

You have probably seen the colorful grid from Hive Systems showing how long passwords of each length survive. The 2026 edition (published July 2026) assumes an attacker renting 16 RTX 5090 graphics cards and a website that stored passwords with bcrypt at a work factor of 10. Under those assumptions, a random 8-character password using all character types takes about 132 years to brute-force.

That result rests on two assumptions:

  1. The password is random. Hive Systems says so directly and notes that non-random passwords fall much faster, because attackers try common and breached passwords first.
  2. The site used a deliberately slow hash. Had it used a fast hash like MD5, the picture would change completely: one RTX 5090 computes about 220 billion MD5 guesses per second in a public hashcat benchmark, which brings the same random 8-character password down to about 4 hours on average.

So the table answers a narrow question: how long exhaustive guessing takes against one storage method. How long your password lasts depends on how you chose it and how the service stores it.

Why passwords people invent are weaker than they look

Attackers rarely try every combination in order. They start with passwords leaked in past breaches, then dictionaries of words and names, then "rules" that mimic human habits: a capital first letter, a year at the end, an exclamation mark, letters swapped for look-alike digits.

That is why Summer2024! is weak despite its 11 characters and all four character types. It follows the most common pattern there is. A line from a song or a famous quote is similar: long, but already on the attacker's lists.

That is why the numbers in this article assume the attacker knows your method. Even knowing you used six words from the EFF list, they still face 7,776 to the sixth power possibilities.

The real threat to an encrypted vault: offline guessing

Online guessing means typing guesses into a real sign-in page. The service can slow this down, block addresses and alert you. In Cappa, the server limits sign-in attempts from each network address, so guessing through the front door is slow.

Offline guessing starts after an attacker steals a copy of the data: a database dump, a leaked backup, a lost laptop. They test guesses on their own hardware, as fast and as long as they like, with no server watching.

This is the scenario an end-to-end encrypted notes app must plan for, and Cappa's security model says so plainly: a stolen database leaves your notes as ciphertext, but the thief can try to guess a weak master password offline, paying the cost of Argon2id for every guess. For the wider picture, see what the server can and can't see and the limits of encryption.

How long to crack a password: fast hash vs Argon2id

In offline guessing, the cost of each guess decides everything.

That is roughly 96 million times fewer guesses per second than MD5 on the same card. Every guess must fill 64 MiB of memory and pass over it three times, so memory speed, not computing power, sets the pace.

163 billion/sMD5 guesses, one RTX 4090
1,703/sArgon2id guesses at Cappa's settings, same card
64 MiBmemory each Argon2id guess needs

The scenarios we use and why

For the calculator below we picked three attackers, leaning in the attacker's favor wherever we had to guess:

  1. Fast hash on one top graphics card: 220 billion guesses per second. The measured MD5 speed of one RTX 5090, showing what careless password storage allows.
  2. Argon2id on one top graphics card: 3,000 guesses per second. Our estimate: the measured 1,703 per second on an RTX 4090, scaled by memory bandwidth (which limits Argon2id) from about 1.0 TB/s on the RTX 4090 to about 1.8 TB/s on the RTX 5090.
  3. Argon2id on a 10,000-card cluster: 30 million guesses per second. Ten thousand of those cards with perfect scaling: far beyond a typical criminal budget, and meant as a pessimistic ceiling.

Try it yourself: pick how the password is made and its length. The calculator shows the average time, meaning the time to search half of all possibilities.

Password lab

Pick how a password is generated and how long it is. Everything is calculated in this page; nothing you choose is stored or sent.

Generated from
64.6 bitsabout 1019 possibilities

Average time to guess

Fast hash (MD5), one RTX 50902 years
Argon2id 64 MiB, one top GPU (estimate)150.2 million years
Argon2id 64 MiB, 10,000-GPU cluster (estimate)15,015 years

Assumes every character or word was picked at random, and that the attacker knows how the password was generated. Passwords people invent themselves are far weaker than their length suggests. Bars use a logarithmic scale.

The chart applies the same math to common password types against the 10,000-card cluster: 2 raised to (bits minus 1), divided by 30 million guesses per second. For the list of known passwords, it is half of one billion guesses.

Any password from a list of 1 billion known passwordsabout 17 seconds
4 random words (EFF list)about 2 years
8 random keyboard charactersabout 3 years
5 random wordsabout 15,000 years
16 random lowercase lettersabout 23 million years
6 random wordsabout 120 million years
7 random wordsabout 900 billion years
16 random keyboard charactersabout 2 × 10¹⁶ years

Logarithmic scale: each step in bar length is ten times more time. Bar length is the base-10 logarithm of the time in seconds.

Average time to guess each password type if every guess costs one Argon2id run (64 MiB, 3 passes) and the attacker makes 30 million guesses per second. Our estimate, as of September 2026.

A password on a known list falls in seconds however slow the hash is, because the attacker simply tries the list. And four random words are about 30 characters long, yet this attacker finds them in about two years on average. Unpredictability counts, not character count.

Passphrase vs password: which should you use?

A passphrase is a password made of several words, like tipper illusion buffed stalemate phosphate gaining (an example only; generate your own). The kind worth using has words picked at random, a method called diceware: roll five dice, read the number and look up the matching word in a list.

The EFF long wordlist has 7,776 words, one for every result of five dice (6 × 6 × 6 × 6 × 6). Each word therefore adds log2(7,776), about 12.9 bits, and six words, the minimum EFF recommends, give about 77.5 bits. Many password managers can generate word-based passphrases for you, which is just as good as dice.

Random passphrase (6 words)

  • About 77.5 bits
  • Easy to remember after a few days of use
  • Long (typically 40 to 50 characters with spaces) but easy to type by hand, even on a phone

Random password (16+ characters)

  • About 105 bits at 16 characters with all character types
  • Almost impossible to remember
  • Best filled in by a password manager; awkward to type on a phone

Both are strong. The weak option sits in between: something you invented, dressed up with a capital letter and a digit. If you want something memorable, let dice or a generator choose the words, and don't swap them for ones you like better.

Why Cappa requires at least 16 characters

A Cappa master password must be 16 to 256 characters long.

  • Characters are counted as Unicode code points. A Polish "ż" counts as one character, not two bytes, while some combined emoji (like family groups) count as several.
  • Your password is normalized, not trimmed. The app converts it to the standard Unicode form called NFC, so the same visible letters typed on different keyboards give the same password. Spaces at the start, at the end and between words all count.
  • Why 16. NIST now requires at least 15 characters for a password used on its own, and CERT Polska recommends at least 14. A Cappa master password carries more weight than a typical login: it is also the source of the key that encrypts your notes, and it may face offline guessing. Sixteen is a floor slightly above both, not a target.

The app checks the length in your browser, because the server never receives your password.

Why 16 characters alone is not enough

Length is necessary but not sufficient: aaaaaaaaaaaaaaaa and passwordpassword both have 16 characters. So whenever you set a new master password (at registration, on a change or during recovery), Cappa checks it in your browser and refuses it if:

  • it has fewer than 5 different characters, such as one character repeated;
  • it is a well-known long phrase, like correct horse battery staple from a famous web comic, compared without regard to case, spaces or punctuation;
  • the open-source estimator zxcvbn-ts predicts it would be found in fewer than about 10 billion (10^10) guesses. The estimator compares your password with bundled lists of about 49,000 common and leaked passwords, plus English words and names. It spots repeats, sequences, keyboard walks like qwerty, dates and letter-for-digit swaps like p4ssw0rd, and it treats your account email and the product name as easy guesses.

The form shows the reason as you type and suggests a generated password or five or more random words. We recommend six.

What NIST and CERT Polska recommend today

The US NIST SP 800-63B-4, finalized in July 2025, is the most cited password guidance. It says:

  • Passwords used as the only factor must be at least 15 characters. Services should allow at least 64.
  • Services "SHALL NOT impose other composition rules", such as requiring a mix of character types.
  • Services "SHALL NOT require subscribers to change passwords periodically", but must force a change if there is evidence of compromise.
  • New passwords must be compared against a blocklist of commonly used, expected or compromised passwords.
  • Services must allow password managers and autofill, and should allow pasting.

CERT Polska points the same way. In June 2025 it raised its recommended minimum from 12 to 14 characters. It suggests building passwords from whole sentences of at least five words and advises against forced periodic changes. Both put length and unpredictability ahead of forced complexity and scheduled changes.

One password, two jobs

In Cappa, your master password signs you in and is the source of the key that unlocks your vault. The browser derives two separate keys from it: one proves your identity to the server, the other opens your vault key and never leaves your device (our Argon2 explainer shows how).

The catch: anyone who learns your master password gets both your sign-in and your notes, whether through phishing (a fake page that looks like Cappa), malware that records keystrokes or someone watching you type. Cappa does not offer a second sign-in factor as of September 2026, so the password carries the full load. Why passkeys resist phishing, and why an encrypted vault still needs a secret of its own, is in What are passkeys?; whether AI changes any of this is in Can AI crack your passwords?

How to create a strong master password

  1. Let chance choose. Six words from a generator (or five dice per word with the EFF list), or 16 or more random characters from a password manager.
  2. Use it only for Cappa, so a breach at another service cannot expose it.
  3. Keep the exact form, spaces included, every time you type it.
  4. Store it safely in a password manager or on paper at home, apart from your recovery code.

FAQ

Is a 12-character password enough?

For an ordinary website account with a unique password, 12 random characters is decent. For a master password that also encrypts data, it is below what NIST (15) and CERT Polska (14) recommend, and Cappa requires 16. If the characters were not chosen at random, they are much weaker than the number suggests.

How long does it take to crack a 16-character password?

It depends on how it was chosen and stored. Sixteen random keyboard characters would take on the order of 10¹⁶ years on average, even for our 10,000-card Argon2id cluster. A 16-character common phrase could fall in seconds if it is on an attacker's list.

Should I change my master password regularly?

No. NIST and CERT Polska both advise against scheduled changes, because they push people toward predictable variations. Change it when you suspect someone learned it, for example after typing it on a suspicious page.

Can I use spaces or Polish letters in my master password?

Yes. Cappa counts characters as Unicode code points and normalizes them, so "ą" or "ż" work the same across devices. Spaces count too, including at the start and the end, so always type the password exactly as you set it.

Written by the Cappa team

We build Cappa, a private Markdown notes app that encrypts your notes on your device before they are synced. We write about the decisions behind it, including the limits, so you can judge them yourself.