Online vs offline
If the attacker has to go through a login form, rate limits and lockouts cap them at a handful of guesses per second. If they’ve stolen the database of hashes, they attack offline at full hardware speed.
Tools · Crack Time
Enter a password to estimate how long it would take to brute-force under five different attacker profiles — from a rate-limited login to a GPU cluster.
| Attacker | Time to crack |
|---|
Calculated locally in your browser. No network, no logging, no telemetry.
If the attacker has to go through a login form, rate limits and lockouts cap them at a handful of guesses per second. If they’ve stolen the database of hashes, they attack offline at full hardware speed.
A slow, salted hash (bcrypt, Argon2, scrypt) deliberately throttles guessing. A fast hash (MD5, SHA-1) lets a GPU try tens of billions per second — which is why how a site stores your password is out of your hands.
You can’t control the attacker’s hardware, only your entropy. Target a password whose offline-GPU crack time reads in millions of years — then even fast hardware can’t catch up. The generator gets you there.
We estimate the password’s entropy in bits, take half the keyspace (the average number of guesses to find it), and divide by an attacker’s guess rate. Each scenario uses a different rate, from ~100 guesses/sec for a throttled login to ~10 trillion/sec for purpose-built hardware.
Attack speed depends entirely on context. A login form that rate-limits attempts is millions of times slower than an attacker who has stolen the password hashes and runs them offline on GPUs — especially if the hashes use a fast algorithm like MD5 or SHA-1 instead of bcrypt or Argon2.
No — they are order-of-magnitude estimates. Real attacks use dictionaries and rules that crack weak passwords far faster than pure brute-force, and hardware keeps getting faster. Treat the offline-GPU column as the realistic worst case and aim for a time measured in centuries there.
For important accounts, you want the offline fast-hash scenario to read in the millions of years. That corresponds to roughly 80+ bits of entropy — about a 13-character random password (all character classes) or an 8-word passphrase.
Ready for the full vault?
Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.