This is a random password matching the shared configuration. The original password was never shared.
Length over complexity!
The chart and table below illustrate how the length and complexity of a password influence the cost of cracking it. As a general rule of thumb, prioritize length over complexity when creating your password. A longer password significantly increases the resources and effort required for an attacker to succeed, offering better protection even with moderate complexity.
- All
- Dict
- Digits
- Lower
- Mix+Dig
- Mixed
| Len | Digits | Lower | Mixed | Mix+Dig | All |
|---|---|---|---|---|---|
| 1 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 |
| 2 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 |
| 3 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 |
| 4 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 |
| 5 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 |
| 6 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.00 | $ 999.02 |
| 7 | $ 999.00 | $ 999.00 | $ 999.02 | $ 999.08 | $ 1.0K |
| 8 | $ 999.00 | $ 999.00 | $ 1.0K | $ 1.0K | $ 1.1K |
| 9 | $ 999.00 | $ 999.13 | $ 1.1K | $ 1.3K | $ 14.7K |
| 10 | $ 999.00 | $ 1.0K | $ 4.5K | $ 21.1K | $ 1.3M |
| 11 | $ 999.00 | $ 1.1K | $ 180.7K | $ 1.2M | $ 121.0M |
| 12 | $ 999.02 | $ 3.3K | $ 9.3M | $ 77.1M | $ 11.4B |
| 13 | $ 999.24 | $ 60.3K | $ 485.9M | $ 4.8B | > $ 1T |
| 14 | $ 1.0K | $ 1.5M | $ 25.3B | $ 296.5B | > $ 1T |
| 15 | $ 1.0K | $ 40.1M | > $ 1T | > $ 1T | > $ 1T |
| 16 | $ 1.2K | $ 1.0B | > $ 1T | > $ 1T | > $ 1T |
| 17 | $ 3.4K | $ 27.1B | > $ 1T | > $ 1T | > $ 1T |
| 18 | $ 24.9K | $ 704.8B | > $ 1T | > $ 1T | > $ 1T |
| 19 | $ 240.1K | > $ 1T | > $ 1T | > $ 1T | > $ 1T |
| 20 | $ 2.4M | > $ 1T | > $ 1T | > $ 1T | > $ 1T |
Cost to crack using MD5 on on-prem (Nvidia RTX 4080 SUPER).
Algorithms matter!
The hashing algorithm used to store your password has a massive impact on security. Fast algorithms like MD5 or SHA-1 can be cracked at billions of attempts per second, while slow algorithms like bcrypt or Argon2 are designed to be computationally expensive. The table below shows cracking costs for common password policies – notice how strong algorithms can make even short passwords expensive to crack.
| Algorithm | OWASP ASVS12 / no complexity | NIST15 / no complexity | BSI #18 / full complexity | CIS10 / mixed case | BSI #225 / no complexity |
|---|---|---|---|---|---|
| MD5 | $ 999.02 | $ 1.0K | $ 1.1K | $ 4.5K | $ 239.1B |
| SHA-1 | $ 999.08 | $ 1.1K | $ 1.5K | $ 12.2K | $ 772.0B |
| SHA-256 | $ 999.18 | $ 1.2K | $ 2.1K | $ 26.8K | > $ 1T |
| SHA-512 | $ 999.52 | $ 1.5K | $ 4.2K | $ 76.7K | > $ 1T |
| MD4 | $ 999.01 | $ 1.0K | $ 1.1K | $ 3.0K | $ 135.5B |
| NTLM | $ 999.01 | $ 1.0K | $ 1.1K | $ 3.0K | $ 135.3B |
| LM | $ 999.03 | $ 1.0K | $ 1.2K | $ 4.7K | $ 259.0B |
| MS Cache (DCC) | $ 999.05 | $ 1.0K | $ 1.3K | $ 8.1K | $ 491.6B |
| MS Cache 2 (DCC2) | $ 2.9K | $ 1.9M | $ 11.4M | $ 271.2M | > $ 1T |
| NetNTLMv1 | $ 999.02 | $ 1.0K | $ 1.1K | $ 4.5K | $ 243.8B |
| NetNTLMv2 | $ 999.33 | $ 1.3K | $ 3.0K | $ 49.2K | > $ 1T |
| Kerberos 5 AS-REQ (etype 23) | $ 1.0K | $ 2.1K | $ 7.6K | $ 158.0K | > $ 1T |
| Kerberoast (TGS-REP etype 23) | $ 1.0K | $ 2.1K | $ 7.7K | $ 158.9K | > $ 1T |
| AS-REP Roast (etype 23) | $ 1.0K | $ 2.1K | $ 7.7K | $ 161.0K | > $ 1T |
| md5crypt (Unix) | $ 1.1K | $ 62.5K | $ 376.1K | $ 8.9M | > $ 1T |
| sha256crypt (Unix) | $ 2.9K | $ 1.9M | $ 11.7M | $ 277.3M | > $ 1T |
| sha512crypt (Unix) | $ 4.4K | $ 3.4M | $ 20.6M | $ 488.6M | > $ 1T |
| bcrypt | $ 17.3K | $ 16.3M | $ 99.2M | $ 2.4B | > $ 1T |
| PBKDF2-HMAC-SHA1 | $ 1.2K | $ 196.1K | $ 1.2M | $ 28.2M | > $ 1T |
| PBKDF2-HMAC-SHA256 | $ 1.4K | $ 440.7K | $ 2.7M | $ 63.6M | > $ 1T |
| PBKDF2-HMAC-SHA512 | $ 2.2K | $ 1.2M | $ 7.5M | $ 177.2M | > $ 1T |
| phpass (WordPress/phpBB) | $ 1.1K | $ 84.5K | $ 509.9K | $ 12.1M | > $ 1T |
| Drupal7 | $ 10.8K | $ 9.8M | $ 59.8M | $ 1.4B | > $ 1T |
| Django (PBKDF2-SHA256) | $ 5.6K | $ 4.6M | $ 28.0M | $ 665.1M | > $ 1T |
| macOS v10.8+ (PBKDF2-SHA512) | $ 2.3K | $ 1.3M | $ 7.7M | $ 181.9M | > $ 1T |
| MS Office 2013 | $ 59.0K | $ 58.0M | $ 353.5M | $ 8.4B | > $ 1T |
| WPA/WPA2 | $ 2.5K | $ 1.5M | $ 9.2M | $ 218.7M | > $ 1T |
| BitLocker | $ 392.0K | $ 391.0M | $ 2.4B | $ 56.5B | > $ 1T |
| VeraCrypt SHA-512 | $ 607.0K | $ 606.1M | $ 3.7B | $ 87.6B | > $ 1T |
| 7-Zip | $ 2.4K | $ 1.4M | $ 8.6M | $ 204.7M | > $ 1T |
| WinZip | $ 1.2K | $ 197.6K | $ 1.2M | $ 28.4M | > $ 1T |
| Bitcoin wallet.dat | $ 116.5K | $ 115.5M | $ 703.9M | $ 16.7B | > $ 1T |
| Ethereum Wallet (PBKDF2) | $ 1.5K | $ 452.4K | $ 2.8M | $ 65.2M | > $ 1T |
Cost to crack password policies using Nvidia RTX 4080 SUPER.
Wordlists are dangerous!
It's crucial to check if your password has been breached or is a common word. Attackers often start with wordlists containing billions of leaked passwords before attempting brute-force attacks. The table below shows how quickly different wordlists can be exhausted – if your password is in one of these lists, it can be cracked almost instantly regardless of its complexity. You should check your password for compromise at haveibeenpwned.com/Passwords.
| Device | Top 10K10K | Weakpass 42.19B | RockYou8.46B | HIBP17.30B | Weakpass AIO26.92B |
|---|---|---|---|---|---|
| Nvidia RTX 4080 SUPER | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 4070 Ti SUPER | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 3090 | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 4070 SUPER | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 3080 Ti | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 4070 | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 2080 Ti | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 3080 | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 4060 Ti | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 3070 | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 3060 Ti | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX A4000 | < 1s | < 1s | < 1s | < 1s | < 1s |
| Nvidia RTX 3060 | < 1s | < 1s | < 1s | < 1s | 1s |
Time to exhaust wordlist using MD5.
Password FAQ
Yes! Your password never leaves your browser. All calculations are performed locally on your device - no data is sent to any server. You can verify this by checking the network tab in your browser's developer tools.
Use a long passphrase with multiple random words, or a mix of uppercase, lowercase, numbers, and symbols. Aim for at least 80 bits of entropy. Consider using a password manager to generate and store unique passwords for each account.
We calculate entropy based on the character pool size and password length. Entropy (in bits) = length × log₂(pool size). The cost is then estimated using real GPU hashrates for various algorithms and current hardware/cloud pricing.
Use a reputable password manager like Bitwarden, 1Password, or KeePass. Generate unique, random passwords for each account. Enable two-factor authentication (2FA) wherever possible for additional security.
Entropy measures the unpredictability of a password in bits. Each bit doubles the number of possible combinations. A password with 40 bits has about 1 trillion possibilities, while 80 bits has over 1 septillion - making brute force attacks impractical.
Different algorithms have vastly different cracking speeds. Fast algorithms like MD5 or SHA-1 can be cracked at billions of attempts per second, while slow algorithms like bcrypt or Argon2 are designed to be computationally expensive, limiting attempts to thousands per second.
Cloud cracking uses rented GPU instances (like AWS) with hourly costs but no upfront investment. On-premises uses purchased hardware with upfront costs plus electricity. Cloud is better for short attacks; on-prem is more economical for extended campaigns.
Generally yes, but character diversity also matters. A 20-character password using only lowercase letters (95 bits) is weaker than a 12-character password using all character types (79 bits). The ideal is both length AND complexity.
Passphrases use multiple random words, making them long yet memorable. A 4-word passphrase from a 7,776-word list has about 51 bits of entropy. Adding numbers or symbols between words significantly increases security while remaining easy to remember.
Attackers use specialized GPU hardware running tools like Hashcat. They try dictionary attacks first, then rule-based mutations, and finally brute force. They prioritize common patterns, which is why random passwords are crucial for security.
A professional penetration test can evaluate your password policies, identify weak credentials, and test your defenses against real-world attacks. turingpoint offers comprehensive security assessments including password audits, Active Directory reviews, and full penetration testing to help secure your organization.
Penetration testing reveals vulnerabilities before attackers find them. Weak passwords are one of the most common entry points for breaches. A professional pentest simulates real attacks on your systems, identifies security gaps, and provides actionable recommendations - potentially saving millions in breach costs.