Brute Force Time
Calculator
Results
- Average crack time (seconds)
- 576,460,752.303423
- Average crack time (years)
- 18.27945
- Average crack time (days)
- 6,671.999447
- Worst-case crack time (years)
- 36.558901
Computing results
| Average crack time (seconds) | 576,460,752.303423 |
| Average crack time (years) | 18.27945 |
| Average crack time (days) | 6,671.999447 |
| Worst-case crack time (years) | 36.558901 |
formula-map diagram
- Average crack time (seconds)
- 576,460,752.303423
- Average crack time (years)
- 18.27945
- Average crack time (days)
- 6,671.999447
- Worst-case crack time (years)
- 36.558901
Computing relationship
Formula
t = 2^H ÷ 2 ÷ guesses_per_second= 576460752.30342
Note
This is a simplified model: it applies the standard computing formula to the numbers you entered and ignores protocol overhead, compression variability, retries, contention and other real-world effects. Size your systems with measured data.
More in Technology and computing
See all →Frequently asked questions
What does this calculator estimate?+
It estimates how long it would take an attacker to guess a password purely by brute force, trying combinations systematically, based on the password's entropy (bits) and an assumed number of guesses the attacker can attempt per second.
Why do estimates for the same password vary so wildly between sources?+
The result depends heavily on the assumed guessing speed, which can range from a few attempts per second (an online login form with lockouts) to billions or trillions per second (an offline attack using specialized hardware against a leaked password database). Always check what guessing-speed assumption is being used.
Does this account for smarter attacks than pure brute force?+
No, real-world attackers rarely try every possible combination in order; they typically use dictionaries, known-password lists, and pattern-based rules that find common or previously breached passwords far faster than brute force would suggest. This means the true time-to-crack for a weak but 'high entropy-looking' password can be much shorter than the brute-force estimate.
Why does this number sometimes come out as an absurdly large timespan?+
For high-entropy passwords, brute-force time estimates can exceed the age of the universe many times over. This isn't a meaningful prediction of real-world risk at that point — it simply illustrates that brute force alone is not a viable attack method against that password, so security concerns shift to other attack vectors like phishing or data breaches.
How should I use this calculator practically?+
Use it to compare the relative strength of different password choices and understand why length matters so much, rather than treating the exact time figure as a literal guarantee — real-world password security depends on more than resistance to brute force alone.