Updated · By Pete Bromfield, IB examiner

IA idea · Cryptography & number theory

How long would it take to guess your password? Counting and logarithms

AA SLAI SLAA HLAI HL Accessible Also in: Probability

Research question

How many guesses does it take, on average and in the worst case, to find passwords built by common rules (length, character sets, words plus digits), and which rule change adds the most security?

Adapt it: change the place, the data or the comparison until the question is yours.

Free: the A–E checklist an examiner uses, by email ↓

Why it makes a good exploration

Counting principles and logarithms answer a question everyone cares about. Comparing realistic password patterns with purely random ones shows why human choices matter more than length rules.

The mathematics you'll need

  • Multiplication principle and permutations
  • Expected number of guesses for a uniform search
  • Logarithms: bits of entropy as log₂ of the number of possibilities
  • Comparing growth: exponential in length, linear in alphabet
  • Probability of guessing within k tries

Course labels show where a technique sits; using maths from outside your course is fine if you explain it clearly and say it is new to you.

Where the data comes from

No personal data. Use rules from real sign-up pages and, for word-based passwords, the size of a dictionary word list you can count.

Cite every source in a footnote where you use it and in your bibliography. Check the licence of any dataset you download.

A possible outline

  1. Count possibilities for several password rules.
  2. Convert to bits and to expected guessing time at a stated guess rate.
  3. Compare adding length with adding symbols.
  4. Model passphrases of random words.
  5. Reflect on human patterns that make the real number much smaller.

Pitfalls that cost marks

  • Never collect or use anyone's real passwords.
  • Treating human-chosen passwords as uniformly random.
  • Using a guess rate with no source; state it as an assumption and vary it.

Showing personal engagement

  • Compare the rules of sites you use.
  • Design a rule that is secure and memorable.
  • Survey (anonymously) which patterns people say they use, not their passwords.

See Criterion C: personal engagement for what examiners look for.

Which course is it for?

CourseFitMaths to lean on
AA SLGood fitMultiplication principle and permutations; Expected number of guesses for a uniform search
AA HLFits, but add an HL techniqueMultiplication principle and permutations; Expected number of guesses for a uniform search
AI SLGood fitMultiplication principle and permutations; Expected number of guesses for a uniform search
AI HLFits, but add an HL techniqueMultiplication principle and permutations; Expected number of guesses for a uniform search

Level: Accessible. A good first extended piece of maths, with room to go deeper. See how the IA differs between AA and AI, SL and HL.

How this idea reaches the top bands

Personal engagement (C)

Build and break your own small cipher or code, invent examples to test each result, and record the conjectures you made and the ones that turned out to be false.

Reflection (D)

Reflect on what each result guarantees and what it doesn't: which errors a check digit misses, which attacks a cipher survives, and how the answer depends on the size of the numbers. For this idea, start with: never collect or use anyone's real passwords — say how it affects your answer.

Use of mathematics (E)

SL: Counting principles, probability or frequency statistics used correctly; any number theory (modular arithmetic, primes) introduced with your own small worked examples and explained, not quoted.

HL: Rigorous proofs (by contradiction or induction) of the number-theory facts you rely on, counting arguments made general, or a statistical attack tested formally.

Criteria A and B (presentation and communication) work the same way for every idea: see the guides to Criterion A and Criterion B.

Taking it further

Model a dictionary attack with a probability distribution over words, or study how many guesses are needed to find one password in a large set.

Extending it for HL

Prove the key result in general (why the check digit catches every single-digit error, why the decryption undoes the encryption) rather than checking examples.

Before you start: the checklist an examiner uses

Every check for Criteria A–E in a 4-page PDF, the mistakes that cost the most marks and a self-assessment grid. We'll email it with a short IA tip every few days, timed to your deadline if you give it. Free — no account, no payment.

Turn this idea into your IA

Similar ideas

All cryptography ideas · AA SL ideas · AI SL ideas · AA HL ideas · AI HL ideas · All 239 IA ideas