Tools · Crack Time

How long would your password survive?

Enter a password to estimate how long it would take to brute-force under five different attacker profiles — from a rate-limited login to a GPU cluster.

0
Length
0
Char pool
0
Entropy (bits)
AttackerTime to crack

Calculated locally in your browser. No network, no logging, no telemetry.

Reading the numbers

Context is everything

Online vs offline

If the attacker has to go through a login form, rate limits and lockouts cap them at a handful of guesses per second. If they’ve stolen the database of hashes, they attack offline at full hardware speed.

The hash matters

A slow, salted hash (bcrypt, Argon2, scrypt) deliberately throttles guessing. A fast hash (MD5, SHA-1) lets a GPU try tens of billions per second — which is why how a site stores your password is out of your hands.

Aim for centuries

You can’t control the attacker’s hardware, only your entropy. Target a password whose offline-GPU crack time reads in millions of years — then even fast hardware can’t catch up. The generator gets you there.

Password Crack-Time Calculator FAQ

Common questions

How is crack time calculated?

We estimate the password’s entropy in bits, take half the keyspace (the average number of guesses to find it), and divide by an attacker’s guess rate. Each scenario uses a different rate, from ~100 guesses/sec for a throttled login to ~10 trillion/sec for purpose-built hardware.

Why are the times so different per row?

Attack speed depends entirely on context. A login form that rate-limits attempts is millions of times slower than an attacker who has stolen the password hashes and runs them offline on GPUs — especially if the hashes use a fast algorithm like MD5 or SHA-1 instead of bcrypt or Argon2.

Are these numbers exact?

No — they are order-of-magnitude estimates. Real attacks use dictionaries and rules that crack weak passwords far faster than pure brute-force, and hardware keeps getting faster. Treat the offline-GPU column as the realistic worst case and aim for a time measured in centuries there.

What crack time should I aim for?

For important accounts, you want the offline fast-hash scenario to read in the millions of years. That corresponds to roughly 80+ bits of entropy — about a 13-character random password (all character classes) or an 8-word passphrase.

Ready for the full vault?

Stop reusing. Start sealing.

Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.