Private Pierce

Password Crack-Time Calculator

Enter a password shape, never a password. The calculator returns an estimate only when every required figure has a source, date, and stated assumptions, and it keeps the model and its limits beside the output.

Scope: Time to search every candidate of a random password at a stated rate. It does not rate a password a person chose.

Privacy: This tool sends nothing and stores nothing; what you enter stays in this tab. The site itself uses analytics and stores a theme setting.

Password crack-time calculator

Enter only a length or word count and listed model choices; never enter a password, passphrase, fragment, hash, username, account, site name, or file.

A whole number from 1 to 128.

The time to search every candidate will appear here, with the arithmetic and the assumptions used.

What this tool does not claim

  • It does not say whether any particular password is good, safe or long enough. It computes a time for a stated model.
  • The model is exhaustive search over uniformly random candidates. A password a person chose is not random; real crackers use breach lists, rules and masks, and the thread this page is built on records a four-class ten-character password falling in seconds. The number printed does not apply to such a password.
  • The rate is a dated benchmark or a vendor's stated table configuration, labelled as one. It is not a measurement of any attacker. Hardware gets cheaper; the figure has a date for that reason.
  • Online and offline are different cases. The tool prints which one it assumed.
  • It says nothing about coercion, a court order, device seizure, phishing, malware, reuse of a password across sites, or a service that stores passwords badly. A time to crack is not a time to compromise.
  • It does not check a password against breach lists and cannot, because it never sees one.
  • It does not rank hash functions, hardware or products, and it has no recommendations.
  • The time of one run is not a forecast. Quantum search (Grover) is mentioned only as a dated note when a source for it is available, and never changes the arithmetic.

A result appears only when each required figure has a source, date, and stated assumptions. If the selected combination lacks that evidence, the calculator prints a refusal and no partial number.

How long does it take to crack a password?

It depends on the hash algorithm, hardware, attack model, and attacker position; the calculator displays the selected inputs and limits beside the result.

Choose the shape of a generated value and an attacker position. The result applies only to that model; it is not a score for a password a person chose and it is not a prediction of when an account or device will be compromised.

Why did two published crack-time charts discussed in the forum thread disagree?

This page does not compare those charts or assign a cause to their gap.

The calculator uses only a selected rate figure with its source, date, and stated assumptions, plus the symbol set shown in the result. It does not claim to reproduce either published chart.

Why can the most-shared vendor table's result change?

This page does not explain the year-to-year change in the most-shared vendor table's results.

A comparison requires the symbol set, algorithm, hardware, mode, cost parameter, date, and stated rate to be stated together. This page does not compare that vendor table with another published table unless the printed time and rate can be reproduced under one documented symbol set. A vendor figure, when available to the tool, is labelled as a vendor-stated table configuration rather than measured benchmark output.

How does the arithmetic work?

Bits equal the length times the base-two logarithm of the symbol count; expected guesses are half the candidates, worst-case guesses are all candidates, and time equals guesses divided by the selected rate, using 365.25 days per year.

  1. Choose character mode or passphrase mode, then select one of the listed character sets or word lists.
  2. Choose an attacker position; a measured offline position also requires an algorithm and hardware pair with a source-backed rate figure.
  3. Read the expected and worst-case outputs, or the probability output for the lockout position, together with the displayed arithmetic.
  4. The assumptions and source list sit directly under the output and keep the model beside the estimate.

Does this estimate score a password someone chose?

No; this page does not infer a chosen password's behavior from its length or character classes, and the calculator never accepts the password itself.

The estimate applies only to a password generated at random from the selected set. A password a person chose is not scored by this calculator.

Does this page define a length where search time stops mattering?

No fixed length is treated as a timeless threshold here; an optional horizon note appears only when both required source-linked figures are available.

When either source-linked horizon figure is unavailable, the note is omitted and the calculator's result is otherwise unchanged. The note never changes the arithmetic and never becomes advice about a particular password.

How are online and offline positions different in the calculator?

Online and offline positions are separate choices with separate rate figures, while the lockout position returns a probability instead of a time.

The selected position is printed in the assumptions. The calculator does not borrow a rate from another position, scale a missing hardware result, or silently substitute a figure from a different algorithm.

What does the password standard say?

NIST SP 800-63B-4 §3.1.1.2 covers minimum password length, and §3.2.2 covers the limit on consecutive failed attempts; the page leaves their wording to source-linked quotations.

When a required source-linked clause is unavailable, its standards line is omitted. The calculator does not fill a missing clause from memory, from a secondary summary, or from a different edition.

What is outside the crack-time model?

The calculator models candidate search time, not compromise through coercion, legal process, device access, phishing, malware, password reuse, or a service's password-storage practice.

A search-time output is not a time-to-compromise estimate. This section sets the boundary of the calculator; it does not evaluate any person's circumstances or prescribe a response.

What does this page not claim?

It does not evaluate a particular password, forecast an attack, rank algorithms or hardware, reproduce an unsupported table comparison, or provide legal, security, purchasing, or personal advice.

  • Each dated rate figure names its configuration and is not a measurement of any attacker.
  • Every output is conditional on the uniformly random candidate model printed with it.
  • The tool does not check breach lists because it never receives a password.
  • The tool does not rank products, vendors, algorithms, hardware, or configurations.
  • A result is an estimate under the displayed assumptions, not a forecast and not a complete threat model.