Password Crack Estimator
Free online password crack estimator. Estimate time to crack password. Your data stays on your device.
Embed this tool
Copy and paste the code below into your website to embed this tool for free. An attribution link to The Util Box is required.
<iframe src="https://www.theutilbox.org/embed/password-estimator" width="600" height="500" frameborder="0" style="border: none; max-width: 100%;" title="Free Password Crack Estimator tool from The Util Box"></iframe> <!-- Free tool by The Util Box — https://www.theutilbox.org/tools/password-estimator --> <a href="https://www.theutilbox.org/tools/password-estimator">Password Crack Estimator by The Util Box</a>
Frequently Asked Questions about Password Crack Estimator
Password Strength Estimator — Entropy and Crack Time, Not Vibes
This password strength estimator computes the entropy of a password in bits and converts that into an estimated crack time under three different attack scenarios. Most strength meters are opinionated lookups that compare your password against a dictionary of common ones. This one shows the arithmetic instead, so you can see exactly where the number comes from and why length dominates everything else.
Everything is calculated in your browser as you type. Nothing is transmitted, stored or logged.
How the Entropy Figure Is Calculated
The estimate is a two-step calculation, and it is worth understanding because it explains the whole output:
- Work out the character pool. The estimator checks which classes your password actually uses and adds their sizes together: 26 for lowercase, 26 for uppercase, 10 for digits, and 33 for symbols. A password using all four has a pool of 95; one using only lowercase has a pool of 26.
- Multiply by length. Entropy is
length × log₂(pool). For a 12-character password over all 95 characters that is 12 × 6.57 ≈ 78.9 bits.
The tool reports the pool size, the length, and bits per character alongside the total, so you can see which of the two levers you are pulling. Adding a character class raises the logarithm only slightly; adding a character raises it linearly. That asymmetry is the entire reason length beats complexity, and it is why "P@ssw0rd!" is far weaker than it looks.
Why There Are Three Crack Times
A single crack-time number is meaningless without knowing who is attacking and with what. The same password faces wildly different odds depending on the situation, so this tool shows three:
| Scenario | Rate | What it represents |
|---|---|---|
| Online attack | 1,000/s | Guessing against a live login, where network latency and rate limiting dominate. |
| Offline, fast hash | 1B/s | A stolen database hashed with something like MD5 or SHA-1, cracked on consumer GPUs. |
| Offline, slow hash | 10K/s | A stolen database using bcrypt, scrypt or Argon2 — deliberately slow to make this expensive. |
The gap between the first and last rows is where the real risk lives. A password that would take centuries against an online login can fall to minutes if the site stores it badly and the database leaks. This is why password storage matters as much as password choice — and why a password manager generating 16+ random characters is the practical answer rather than trying to out-think the formula.
The Honest Limitations of This Kind of Estimate
- It assumes the password is random. The formula treats your password as
uniformly drawn from the pool. Real people choose patterns, so actual strength is usually lower than the
estimate.
Summer2024!scores as if it were random, but a dictionary attack targeted at seasonal passwords finds it instantly. - It does not detect repeats.
aaaaaaaaaaaaearns a real pool-based score while containing almost no information. Entropy calculations are blind to repetition. - It does not check breached lists. A password's real-world risk is dominated by whether it has already appeared in a breach, which no offline formula can know.
- Crack times are averages, not guarantees. A determined attacker with specialised hardware can beat these figures. Treat them as relative guidance, not a security boundary.
Used with those caveats, the numbers are genuinely useful — mainly as a way to confirm that a long random password is in the right range, and to see immediately how little a single extra character class buys you.
Related Security Tools
- Password Generator — rather than evaluating a password you invented, generate one that needs no defending.
- Password Policy Checker — test a candidate against a specific site's stated requirements.
- Two-Factor Auth Generator — TOTP codes, which mean a leaked password alone is not enough.
- bcrypt Generator — the correct way to hash a password for storage, as opposed to this tool's fast-hash assumptions.
- Hash Generator — checksums and digests for non-password data.
- Random Token Generator — API keys and session tokens, where predictability is the only real risk.