{
  "slug": "password-crack-time",
  "title": "Password Crack Time Calculator",
  "heading": "Password Crack Time by Entropy Calculator",
  "category": "math",
  "url": "https://www.revenuelab.fyi/toolbox/password-crack-time",
  "summary": "Estimate how long a password takes to brute-force based on entropy and hardware.",
  "description": "Password strength comes down to entropy: the number of possible combinations, expressed as character set size raised to the password length. A password entropy in bits is log2(character-set-size^length), and crack time is the search space divided by guesses per second, assuming worst-case brute force with no dictionary shortcuts. This calculator computes entropy from your character set choices (lowercase, uppercase, digits, symbols) and length, then estimates crack time against a modern GPU cracking rig doing roughly 10 billion guesses per second for a fast unsalted hash like MD5, versus a properly salted and stretched hash like bcrypt at roughly 10,000-100,000 guesses per second. This is why hashing algorithm choice matters as much as password length: the same 12-character password takes seconds against a fast hash and centuries against bcrypt. Real-world cracking also uses dictionaries, rule-based mutations, and leaked password lists, which cut effective crack time far below the pure brute-force number for common patterns, so entropy calculations are a ceiling, not a guarantee.",
  "formula": "Entropy (bits) = length × log2(charset size). Crack time (seconds) = 2^entropy ÷ (2 × guesses per second), using half the space as the average case.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=password-crack-time",
  "inputs": [
    {
      "id": "length",
      "label": "Password length",
      "kind": "number",
      "hint": null,
      "default": 12,
      "unit": null,
      "min": 1,
      "max": 64
    },
    {
      "id": "lowercase",
      "label": "Includes lowercase letters?",
      "kind": "select",
      "hint": null,
      "default": "yes",
      "options": [
        {
          "value": "yes",
          "label": "Yes"
        },
        {
          "value": "no",
          "label": "No"
        }
      ]
    },
    {
      "id": "uppercase",
      "label": "Includes uppercase letters?",
      "kind": "select",
      "hint": null,
      "default": "yes",
      "options": [
        {
          "value": "yes",
          "label": "Yes"
        },
        {
          "value": "no",
          "label": "No"
        }
      ]
    },
    {
      "id": "digits",
      "label": "Includes digits?",
      "kind": "select",
      "hint": null,
      "default": "yes",
      "options": [
        {
          "value": "yes",
          "label": "Yes"
        },
        {
          "value": "no",
          "label": "No"
        }
      ]
    },
    {
      "id": "symbols",
      "label": "Includes symbols?",
      "kind": "select",
      "hint": null,
      "default": "yes",
      "options": [
        {
          "value": "yes",
          "label": "Yes"
        },
        {
          "value": "no",
          "label": "No"
        }
      ]
    },
    {
      "id": "hashType",
      "label": "Storage / attack scenario",
      "kind": "select",
      "hint": null,
      "default": "10000000000",
      "options": [
        {
          "value": "10000000000",
          "label": "Fast unsalted hash (MD5/SHA1) — GPU rig, 10B/sec"
        },
        {
          "value": "1000000",
          "label": "SHA-256 unsalted — 1M/sec"
        },
        {
          "value": "10000",
          "label": "bcrypt/scrypt/Argon2, properly configured — 10k/sec"
        },
        {
          "value": "100",
          "label": "Online login throttled — 100/sec"
        }
      ]
    }
  ],
  "outputs": [
    {
      "id": "years",
      "label": "Estimated average crack time (years)",
      "format": "decimal",
      "hint": null,
      "primary": true
    },
    {
      "id": "entropy",
      "label": "Entropy",
      "format": "decimal",
      "hint": "bits",
      "primary": false
    },
    {
      "id": "avgSeconds",
      "label": "Average crack time (seconds)",
      "format": "raw",
      "hint": null,
      "primary": false
    },
    {
      "id": "totalCombos",
      "label": "Total possible combinations",
      "format": "raw",
      "hint": null,
      "primary": false
    },
    {
      "id": "charset",
      "label": "Character set size",
      "format": "number",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Password length: 12",
      "Includes lowercase letters?: Yes",
      "Includes uppercase letters?: Yes",
      "Includes digits?: Yes",
      "Includes symbols?: Yes",
      "Storage / attack scenario: Fast unsalted hash (MD5/SHA1) — GPU rig, 10B/sec"
    ],
    "outputs": [
      "Estimated average crack time (years): 754,050.24",
      "Entropy: 78.7",
      "Average crack time (seconds): 23,796,015,740,712.83",
      "Total possible combinations: 475,920,314,814,256,650,000,000",
      "Character set size: 94"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter password length.",
      "Enter includes lowercase letters?.",
      "Enter includes uppercase letters?.",
      "Enter includes digits?.",
      "Enter includes symbols?.",
      "Enter storage / attack scenario.",
      "Read your estimated average crack time (years) on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "length": 7,
        "lowercase": "yes",
        "uppercase": "yes",
        "digits": "yes",
        "symbols": "yes",
        "hashType": "10000000000"
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "length": 12,
        "lowercase": "yes",
        "uppercase": "yes",
        "digits": "yes",
        "symbols": "yes",
        "hashType": "10000000000"
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "length": 19,
        "lowercase": "yes",
        "uppercase": "yes",
        "digits": "yes",
        "symbols": "yes",
        "hashType": "10000000000"
      }
    }
  ],
  "limitations": [
    "Results are rounded for display; the underlying calculation keeps full precision.",
    "Very large or very small inputs may hit floating-point limits in the browser.",
    "Inputs outside the accepted range are clamped rather than rejected."
  ],
  "faq": [
    {
      "q": "Why does the hashing algorithm matter more than password complexity sometimes?",
      "a": "A fast hash like unsalted MD5 lets a modern GPU rig test 10+ billion guesses per second, while bcrypt deliberately slows verification to around 10,000 guesses per second by design. That six-order-of-magnitude difference means a 10-character password on bcrypt can outlast a 16-character password on MD5, which is why choosing a slow, salted hashing algorithm is a bigger security lever than most password policy debates."
    },
    {
      "q": "Is this calculator's estimate realistic against real attackers?",
      "a": "It's a ceiling for pure brute force with no shortcuts. Real attackers use dictionaries, leaked password databases, and mutation rules (adding numbers, capitalizing first letters) that crack common patterns in minutes even at high entropy, so a random 12-character string is far safer than a 16-character phrase built from dictionary words with predictable substitutions."
    },
    {
      "q": "What length should I actually require for passwords?",
      "a": "NIST SP 800-63B recommends minimum 8 characters with no forced complexity rules or periodic rotation, instead prioritizing length, breach-list screening, and MFA. For anything protecting sensitive data, 14+ character passphrases or a password manager generating random 16+ character strings is the practical modern standard."
    },
    {
      "q": "Does adding one more character really matter that much?",
      "a": "Yes, dramatically, because entropy grows exponentially with length. Adding a single character to a 62-character-set password roughly multiplies the search space by 62x, which can turn a crackable-in-hours password into one that takes decades, far more impact than swapping a letter for a symbol."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/mfa-rollout-roi",
    "https://www.revenuelab.fyi/toolbox/phishing-training-roi"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Password Crack Time Calculator (https://www.revenuelab.fyi/toolbox/password-crack-time)"
}