Skip to main content

Security tool

Brute Force Attack Time Estimator

Understand how key spacing, entropy levels, and hashing algorithms determine password security. Adjust lengths, character complexities, and computing budgets to witness the math of exponential complexity.

Educational Playground

This simulator operates completely locally on your system. It is designed to illustrate password strength mathematical properties without sending any inputs to external servers.

1. Choose Password Options

Type an active password to analyze it directly, or tweak parameters below to estimate a hypothetical target.

9 characters

2. Attack Speed Configuration

Select standard hardware options or specify custom configurations to estimate cracking times.

3. Estimate Calculations

Password Strength:Reasonable
Entropy: 46.5 bitsMinimum target: 60 bits
Total Keyspace

101559956668416

Possible combinations (36^9)
Cracking Speed

100,000 H/s

Attempts processed per sec

Average Crack Time (50% keyspace)

16.1 years

Worst Case Time (100% keyspace)

32.2 years

4. Visual Decryption Trace

Educational Trace
β€’
β€’
β€’
β€’
β€’
β€’
β€’
β€’
β€’
Simulated Attempts:0
Matched Characters:0 / 9 (0%)

Exponential Growth Math

Adding complexity increases $S$ linearly, but adding length increases $L$ exponentially. For example, adding one symbol to a 10-char password increases keyspace by a small factor, but making it 14 chars makes it billions of times harder to crack.

Offline vs. Online Hashing

Online attacks target APIs that rate-limit logins, restricting speed to e.g. 10 H/s. Offline attacks happen when databases are leaked, letting attackers run cracking rigs directly on hashes at billions of keys per second.

The Slow-Hashing Defense

KDF algorithms (like Scrypt, PBKDF2, Bcrypt, and Argon2) are deliberately slow. They raise the computation cost of checking keys, reducing an attacker's speed from billions of hashes per second to mere hundreds, saving user databases.