Password Entropy & NIST SP 800-63B Guidelines
Password strength is mathematically defined by its information entropy measured in bits ($E = L \times \log_2(R)$), where $L$ is password length and $R$ is character set size.
< 40 Bits Entropy
Very Weak
Cracked in seconds with modern GPUs.
60 - 80 Bits Entropy
Moderate / Good
Sufficient for low-risk online accounts.
> 100 Bits Entropy
Military Grade
Immune to offline brute-force attacks.