Password Strength & Brute-Force Crack Time Estimator
Analyze password entropy, character search spaces, and theoretical brute-force cracking durations across online rate-limited, fast online, and offline GPU attack scenarios.
100% Secure & Client-Side: Evaluated entirely in local browser RAM. No passwords are ever stored or transmitted.
Estimated Time to Crack (Brute-Force Scenarios)
Character Set Composition
The Mathematics of Password Cracking and Keyspace Search Complexity
In computational cryptanalysis, brute-force search represents the most fundamental attack against any authentication secret. A brute-force algorithm systematically generates candidate keys across the search space until a cryptographic hash match occurs.
The time required to crack a password depends directly on three mathematical variables:
- Character Pool Size ($R$): The distinct set of glyphs available (e.g., 26 lowercase, 26 uppercase, 10 digits, 32 ASCII punctuation symbols).
- Password Length ($L$): The number of characters in the string. Total possibilities equal $R^L$.
- Attack Velocity ($V$): The number of candidate hashes or login attempts evaluated per second by the adversary.
Expected Crack Time Formula
Assuming a uniform distribution of candidate attempts, an attacker will on average locate the target password after testing exactly half the total keyspace:
T = (R^L) / (2 × V)For example, an 8-character password composed exclusively of lowercase English letters has a search space of $26^8 \approx 2.088 \times 10^11$ combinations. Evaluated against an 8-GPU Hashcat rig computing unsalted NTLM hashes at 100 billion guesses/second (100 GH/s):
T = (2.088 × 10^11) / (2 × 100 × 10^9) ≈ 1.04 secondsIn contrast, expanding that password to 16 characters drawn from a full 94-character pool expands the search space to $94^16 \approx 3.71 \times 10^31$. Under that same 100 GH/s GPU cluster:
T = (3.71 × 10^31) / (2 × 10^11) ≈ 1.85 × 10^20 seconds (> 5.8 trillion years)Attack Vector Spectrum: Online vs Offline Cracking
| Vector Category | Testing Velocity | Constraining Mechanism | Primary Defense |
|---|---|---|---|
| Online Throttled | 10 - 100 / hour | IP rate limits, account lockouts, CAPTCHAs | Web Application Firewall (WAF) |
| Online Unthrottled | 1,000 - 50,000 / sec | Network bandwidth, backend server latency | Strict API gateway rate limiting |
| Offline Fast Hashes (MD5/NTLM) | 100 - 1,000 Billion / sec | GPU clock cycles, PCIe bus bandwidth | Upgrade to Argon2id / bcrypt |
| Offline Slow Hashes (Argon2/bcrypt) | 1,000 - 50,000 / sec | Memory bandwidth, cache latency | High work factor (cost parameters) |
Why Dictionary and Mask Attacks Subvert Pure Mathematical Calculations
The theoretical crack times shown in brute-force calculators represent worst-case mathematical bounds where an adversary is forced to test character permutations blindly. In reality, human beings rarely generate uniformly random passwords:
- Breach Dictionaries: Threat actors maintain databases containing tens of billions of real-world passwords leaked from historical data breaches (such as Collection #1-5, RockYou2024). A password that exists in these dictionaries is cracked in zero seconds through precomputed lookup tables.
- Rule-Based Expansions: Attackers apply grammatical transformation rules (e.g. capitalizing first characters, appending four-digit birth years, substituting letters with symbols). A password like
Tr@vel2026!has high theoretical character diversity but takes only milliseconds to crack via dictionary rules.