"It would take a computer 400 years to crack this password" is a reassuring thing for a strength meter to say. Whether it is true depends on three things the meter usually does not tell you: how the password was chosen, how the website stored it, and how fast the attacker can guess. This guide puts real numbers on each.
Attackers rarely guess at the login page
Typing guesses into a website's login form is slow, and sites lock accounts or add delays after a few failures. At a generous ten guesses a second, even a weak password holds out for a while. Real cracking happens after a breach. Attackers copy a site's user database, which stores each password as a hash, a one-way fingerprint, and then test guesses on their own hardware by hashing each candidate and looking for a match. Nothing slows them down except the cost of computing hashes.
That cost depends on the site. A fast, general-purpose hash like MD5 or SHA-1 can be computed tens of billions of times a second on a single modern graphics card, and a rig of several cards reaches about a trillion. A password-specific hash like bcrypt, scrypt or Argon2 is deliberately slow, holding each card to thousands of guesses a second. You do not get to choose which one a site uses, and many breaches have revealed fast hashes, so assume the worst.
The numbers for random passwords
For a password generated randomly, the attacker's best strategy is to try every possibility, and on average they find it halfway through. Here is the average time at a trillion guesses a second against a fast hash, and at 100,000 a second against bcrypt:
| Random password | Fast hash, 10¹² per second | bcrypt, 10⁵ per second |
|---|---|---|
| 8 characters, all types | about 30 minutes | about 570 years |
| 10 characters, all types | about 160 days | about 4.4 million years |
| 12 lowercase letters | about 13 hours | about 15,000 years |
| 12 characters, all types | about 3,400 years | about 34 billion years |
| 16 lowercase letters | about 690 years | about 7 billion years |
| 4 random words | about 30 minutes | about 580 years |
| 6 random words | about 3,500 years | about 35 billion years |
"All types" means upper and lowercase letters, digits and symbols, 88 characters in all. The words come from the EFF's list of 7,776. Two things stand out. Storage matters enormously: the same 8-character password survives centuries or half an hour depending on the site. And length scales better than variety: every extra character multiplies the work again, so a 20-character password of lowercase letters beats a 14-character one that uses every symbol on the keyboard.
Why human passwords fall in seconds
Everything above assumes a random password. Passwords people invent are not, and attackers never start by trying every combination. They start with lists of real passwords from past breaches, hundreds of millions of them, then apply rules that mimic how people modify words: capitalize the first letter, swap a for @, add a year, add an exclamation mark. "Summer2024!" is eleven characters long and uses all four character types, and it falls in the first second of any serious attack, because thousands of people chose it before you.
This is why strength meters that count character types mislead. They score P@ssw0rd1! as strong. The only passwords whose strength you can actually calculate are random ones, which is what a generator is for.
Reuse is the bigger risk
Most accounts are not taken over by cracking at all. Once a password is exposed in any breach, attackers try the same email and password on hundreds of other sites automatically, an attack called credential stuffing. A flawless password reused on ten sites is only as safe as the weakest of those ten. You can check whether your email address has appeared in known breaches at haveibeenpwned.com.
What to actually do
- Use a password manager, and let it generate a different random password of 16 or more characters for every site.
- For the few passwords you must remember, such as the manager itself or your computer login, use a passphrase of six random words. The Strong Password Generator makes both, and shows the entropy and crack-time estimates for each.
- Turn on two-factor authentication, preferably an authenticator app or a security key rather than text messages, starting with your email account, since email can reset every other password you have.
- When a site you use announces a breach, change that password, and anywhere you reused it.
Strong Password Generator: Random passwords or passphrases, with entropy and crack time.
Open the tool
