Keypad Lock Code Entropy Calculator
Estimate valid PIN combinations, entropy bits, blacklist effects, guess probability, and lockout timing for owner-side keypad lock planning without exposing bypass steps.
Entropy result
| Rule | Combination formula | Example | Owner-side use |
|---|---|---|---|
| Repeats allowed | choices^length | 10^6 = 1,000,000 | Most flexible and easiest to explain. |
| No adjacent repeats | choices x (choices - 1)^(length - 1) | 10 x 9^5 = 590,490 | Blocks codes like 1007 and 5772. |
| No digit reused | choices! / (choices - length)! | 10P6 = 151,200 | Can reduce space sharply for long PINs. |
| Blacklist adjustment | valid base - blocked accepted codes | 1,000,000 - 500 | Removes known weak or personal codes. |
| Entropy bits | log2(valid combinations) | log2(1,000,000) = 19.93 | Compares code spaces on the same scale. |
| PIN setup | Valid combinations | Entropy bits | Note |
|---|---|---|---|
| 4 digits, repeats allowed | 10,000 | 13.29 | Convenient but small code space. |
| 5 digits, repeats allowed | 100,000 | 16.61 | Ten times a 4-digit PIN. |
| 6 digits, repeats allowed | 1,000,000 | 19.93 | Common stronger keypad baseline. |
| 6 digits, no repeats | 151,200 | 17.21 | Rule is memorable but reduces space. |
| 8 digits, repeats allowed | 100,000,000 | 26.58 | Much stronger when users can remember it. |
| Attempts | Cooldown | Entry time | Allowed guesses per hour |
|---|---|---|---|
| 5 | 30 sec | 4 sec | 360 guesses/hr |
| 5 | 120 sec | 4 sec | 129 guesses/hr |
| 3 | 300 sec | 4 sec | 34 guesses/hr |
| 10 | 300 sec | 4 sec | 106 guesses/hr |
| 3 | 900 sec | 4 sec | 12 guesses/hr |
| Result band | Entropy bits | Code-space meaning | Planning note |
|---|---|---|---|
| Very small | Under 14 | About 4 decimal digits | Use longer codes and lockouts. |
| Basic | 14 to 18 | 5 digits or restricted 6 | Blacklist obvious patterns. |
| Good | 18 to 24 | 6 to 7 digits | Strong for many home keypads. |
| Strong | 24 to 30 | 8 to 9 digits | Good for admin or high-risk doors. |
| Very strong | 30+ | 10+ digits or larger key set | Check usability and recovery process. |
After plugging in your lockout settings and PIN length, the calculator does math for you. No need to compute permutation formulas or logarithms on your own.
What it tells you is that even with a standard four digit code, you’re only getting roughly thirteen bits of entropy. That’s a fancy way of saying it has ten thousand possible combinations. At a rate of guessing one code every few seconds, an attacker could theoreticaly try them all within an afternoon (without triggering any alarms). It is not much of a barrier.
How to Make Your Smart Lock Safe
Switching to a six digit code completely change the game. With just this simple jump, you add nearly seven bits of randomness, which increases the space by a factor of one hundred. The time to crack it transition from a casual afternoon project to a multi-day commitment if they’re doing it manually.
Instead of using long codes, many people attempt to offset that risk by restricting patterns or nearby keys. If I block 1-2-3-4, they reason, that will make my code more difficult to guess! Wrong. Diagonal swipes are just a small part of the overall space. Banning them removes a few percentages, cutting off a couple of points but doing little to reduce expected value of the overall attack.
Only length matter as a viable knob. Mathematically speaking, a code with no restrictions and a longer length is better than any code with a shorter length and complicated ban rules. When you pit a six digit, unrestricted code against a five digit, restricted one in tool, the former wins; again and again.
But just as importantly: What does your lock do if it makes a mistake? The calculator takes both cooldowns and attempt limits into account. These factors shifts the entire threat model from “code cracker” to “waiter. Does your smart lock start locking you out after five bad tries? Now we’re in the realm of the waiting game for attackers.
Does it have a two minute cooldown? An intruder can enter maybe fifteen code an hour. Glacially slow by computer standards, sure, but that’s all it takes to be effective at thwarting physical break-in, where stealth matters. The page has a timing reference table that shows just how much a small lockout duration cut down the number of guesses an attacker have in a given day. Good hardware design will protect you here; no amount of clever coding habit ever could of.
Intuition also fails us in other ways, such as blacklisting: many systems will automaticly reject certain types of passwords, like sequential numbers or dates (e.g., birthdays or anniversaries). That means that the list of potential “safe” choices for your loved ones to select from has been reduced, but so has the number of possible combinations overall. Even worse, if an attacker knows about your blacklist, he’s already ahead of the game. He doesn’t have to guess at a number like 1990; it is already ruled out.
The entropy calculation accounts for these restrictions and provides a practical estimate for how much searching remain. Don’t use blacklists to protect your door. Only use them to keep family members away from setting obvious passwords.
So what makes a good smart lock? At its heart, smart locks is a balance between ease of use and reasonable resistance. Something too hard to get into won’t be used, but something too easy will get picked by an opportunist. A six digit pin with a stern lockout policy is normaly a happy medium for home users: not so long that you need photographic memories in every household member, but long enough to make guesswork impractical.
Finally, your keypad isn’t a vault. It’s a friction point. It slows things down making it difficult for unauthorized people to get in, but also noticeable enough when they do. Knowing how many combinations are sitting behind those plastic buttons gives you the opportunity to set rules that keep you safe without losing convenience.
Because that quiet click at the door should stay that way. It is a minor annoyance, easily dismissed as you continue with your dinner.
