The Util Box

Password Crack Estimator

Free online password crack estimator. Estimate time to crack password. Your data stays on your device.

Enter a password above to estimate crack time

Embed this tool

Copy and paste the code below into your website to embed this tool for free. An attribution link to The Util Box is required.

<iframe src="https://www.theutilbox.org/embed/password-estimator" width="600" height="500" frameborder="0" style="border: none; max-width: 100%;" title="Free Password Crack Estimator tool from The Util Box"></iframe>
<!-- Free tool by The Util Box — https://www.theutilbox.org/tools/password-estimator -->
<a href="https://www.theutilbox.org/tools/password-estimator">Password Crack Estimator by The Util Box</a>

Frequently Asked Questions about Password Crack Estimator

Password Strength Estimator — Entropy and Crack Time, Not Vibes

This password strength estimator computes the entropy of a password in bits and converts that into an estimated crack time under three different attack scenarios. Most strength meters are opinionated lookups that compare your password against a dictionary of common ones. This one shows the arithmetic instead, so you can see exactly where the number comes from and why length dominates everything else.

Everything is calculated in your browser as you type. Nothing is transmitted, stored or logged.

How the Entropy Figure Is Calculated

The estimate is a two-step calculation, and it is worth understanding because it explains the whole output:

  1. Work out the character pool. The estimator checks which classes your password actually uses and adds their sizes together: 26 for lowercase, 26 for uppercase, 10 for digits, and 33 for symbols. A password using all four has a pool of 95; one using only lowercase has a pool of 26.
  2. Multiply by length. Entropy is length × log₂(pool). For a 12-character password over all 95 characters that is 12 × 6.57 ≈ 78.9 bits.

The tool reports the pool size, the length, and bits per character alongside the total, so you can see which of the two levers you are pulling. Adding a character class raises the logarithm only slightly; adding a character raises it linearly. That asymmetry is the entire reason length beats complexity, and it is why "P@ssw0rd!" is far weaker than it looks.

Why There Are Three Crack Times

A single crack-time number is meaningless without knowing who is attacking and with what. The same password faces wildly different odds depending on the situation, so this tool shows three:

Scenario Rate What it represents
Online attack 1,000/s Guessing against a live login, where network latency and rate limiting dominate.
Offline, fast hash 1B/s A stolen database hashed with something like MD5 or SHA-1, cracked on consumer GPUs.
Offline, slow hash 10K/s A stolen database using bcrypt, scrypt or Argon2 — deliberately slow to make this expensive.

The gap between the first and last rows is where the real risk lives. A password that would take centuries against an online login can fall to minutes if the site stores it badly and the database leaks. This is why password storage matters as much as password choice — and why a password manager generating 16+ random characters is the practical answer rather than trying to out-think the formula.

The Honest Limitations of This Kind of Estimate

  • It assumes the password is random. The formula treats your password as uniformly drawn from the pool. Real people choose patterns, so actual strength is usually lower than the estimate. Summer2024! scores as if it were random, but a dictionary attack targeted at seasonal passwords finds it instantly.
  • It does not detect repeats. aaaaaaaaaaaa earns a real pool-based score while containing almost no information. Entropy calculations are blind to repetition.
  • It does not check breached lists. A password's real-world risk is dominated by whether it has already appeared in a breach, which no offline formula can know.
  • Crack times are averages, not guarantees. A determined attacker with specialised hardware can beat these figures. Treat them as relative guidance, not a security boundary.

Used with those caveats, the numbers are genuinely useful — mainly as a way to confirm that a long random password is in the right range, and to see immediately how little a single extra character class buys you.

Related Security Tools