Disclaimer: We sustain our work & review products through paid collaborations.
Password Strength Meters Aren’t as Useful as You Might Think

Password Strength Meters Aren’t as Useful as You Might Think


Passwords are the first line of defense for safeguarding data stored in online accounts, although there have been many proposals for replacements: just consider the presence of biometrics on smartphones. Now, every high-end smartphone includes some sort of biometric identification feature, whether that’s an iris or fingerprint scanner or the new facial recognition system called Face ID by Apple.

How secure is my password

It seems like more than half a century of password use in computing wasn’t enough for scientists and security experts to figure out how people create their passwords. Although the rapid adoption of online services has also brought numerous changes to password security, user patterns don’t seem to change with them. Internet users continue to use weak passwords – as demonstrated in the list of the worst passwords – with most users refusing to consider the issue even after a series of massive breaches.

To address this growing problem of easy-to-guess passwords, system administrators and service providers (including tech giants such as Google and Apple) have adopted various different approaches. Password policies were changed and many popular websites encourage users to create stronger passwords by employing password meters.

A password meter serves to check the strength of the password that the user has entered and, by design, are usually presented as a colored bar indicating a weak password with a short red bar and a strong password with a long green bar. The visual information is underpinned by a single-word qualification: weak, medium, normal, fair, strong, or the like.

Reuse passwords

The fundamental problem of password strength meters

Researchers at Microsoft have found that the use of password strength meters has had a positive impact on password security because those “who saw a meter tended to choose stronger passwords than those who didn’t”. But password checkers seem to suffer from a fundamental problem; they are generally inconsistent, as reported by multiple researchers studying the nature of these utilities.

After evaluating the password checker of 11 prominent service providers – Apple, Dropbox, Drupal, eBay, FedEx, Google, Microsoft, PayPal, Skype, Twitter, and Yahoo! – researchers at the Concordia University of Montreal have concluded that “it is evident that the commonly used meters are highly inconsistent, fail to provide coherent feedback on user choices, and sometimes provide strength measurements that are blatantly misleading”.

During password creation these meters instantly evaluate the password based on the following aspects:

  • Character set and length requirements
  • Strength scales and labels
  • User information
  • Types (client-side or server-side)
  • Monotonicity
  • Entropy estimates and blacklists

The problem that these password meters suffer from is that they seem to focus on measuring entropy. Measuring user-chosen password entropy is problematic, especially with a rule-based metric the researchers say, so there is a need for better password checkers that is currently awaiting proper implementation. Another issue is that though passwords with a lot of entropy are hard to guess, it is an easy task for password crackers. In the end, these meters create a false sense of safety.

Considering the widespread use of password strength meters, web consultant Mark Stockley put to the test five of the “most popular” checkers using a jQuery plugin. In this test, he used five of the most common passwords: abc123, trustno1, ncc1701, iloveyou!, and primetime21. These passwords would get cracked in less than a second so their use is not recommended at all, but he was curious to find out whether these insecure passwords would be approved by the various strength meters.

60% off RoboForm for Best Reviews readers
RoboForm logo
Commit to RoboForm using Best Reviews' exclusive discount and enjoy a discount of 60% off the regular price.
/goto/roboform/ Click to show code

Unfortunately, all the password checkers failed and, more importantly, were inconsistent: the same insecure password was deemed weak by one but good by another. In our non-scientific test Google accepted any of the insecure passwords, while Dropbox, Apple and eBay raised the red flag marking ‘abc123′ as weak, while interestingly ‘primetime21′ was accepted by eBay.

How to protect your passwords

This raises concerns regarding whether the average user should trust any of these strength meters implemented on a website. Our recommendation is to either use one of our recipes to come up with a strong password (and, of course, remember it) or a password manager. The latter streamlines password generation and recollection process and automatically provides cryptographically secure passwords.

website scam and password theft

In case you are trying to figure out whether your older passwords are secure enough, the easiest way is to import them into your preferred password manager, which will then take care of the rest. The app will notify you if a password is weak, and if so you can use the built-in password generator to replace it with a secure one.

For other internet users looking to check their password security, there are a handful of utilities they can use. Our recommendation is to only use these legitimate sites, either LastPass’s or Random-Ize’s password checker. For other sites, be sure to avoid pasting your real password into the checker field, especially not the password to any online bank account because it might end up stored in a password database on the ‘dark web’. The consequences are clear, too, since we are always reading alarming headlines of emptied bank accounts on a regular basis.


Best password managers of 2025

Editors' choice

RoboForm

Editor's rating:
Identifies weak, reused passwords
Future-ready, seamless logins
Easy to use
Budget-friendly
Families

LastPass

Editor's rating:
Logical interface
Automated password categorization
Advanced mobile version
Various two-factor authentication options
Businesses

1Password

Editor's rating:
Keeps your data fully private
Protects against unauthorized access
Protects against unauthorized access
One-time password support
Security features

Keeper

Editor's rating:
Protects against data breaches
Works on all major devices
Budget-friendly
Help when you need it
Personal use

NordPass Personal

Editor's rating:
Keeps data safe and encrypted
Creates strong, unique passwords
Great value at no cost
Affordable premium upgrade
Password sharing

Dashlane

Editor's rating:
Updates weak passwords quickly
Encrypts your online traffic
Easy migration from other tools
Full mobile functionality
Local storage

Enpass

Editor's rating:
Comprehensive password management
No cost on desktops
Full control of your data
Keeps your info fully secure

Discussions

Share your thoughts, ask questions, and connect with other users. Your feedback helps our community make better decisions.

©2012-2025 Best Reviews, a clovio brand – All rights reserved