* Theoretical search-space estimate ($R^L$). Real-world cracking speed depends on hashing algorithms (BCrypt vs MD5), salts, rate limiting, and rule-based dictionary attacks.
Contains predictable numeric sequences (e.g. '1234' or '9876') targeted by dictionary rules.
Uses obvious character swaps (e.g. '@' for 'a', '0' for 'o') heavily targeted by rule-based hybrid attacks.
Traditional password meters only check whether four character types are present. Our analyzer combines structural heuristics with mathematical entropy calculations:
Estimating crack time requires dividing the total combinatorial search space ($2^H$) by estimated attack rates:
Modern NIST guidelines recommend prioritizing password length (minimum 15–16 characters) and passphrases over mandatory periodic expiration or arbitrary composition rules that encourage predictable substitutions.
Scenario: Evaluating a password that relies on common character substitutions.
P@ssw0rd2024!
Entropy: ~42 bits (Weak) | Crack Time (8-GPU Rig): < 2 seconds
Exposes dictionary word roots and predictable year suffixes vulnerable to hashcat rules.
Scenario: Evaluating a four-word random Diceware-style passphrase.
correct-horse-battery-staple
Entropy: ~94 bits (Very Strong) | Crack Time: > 10,000 years
Demonstrates how length combined with natural randomness produces exceptional crack resistance.
Generate cryptographically secure passwords that achieve top strength scores.
Compute SHA-256 and SHA-512 hashes of passwords.
Create random secret keys and cryptographic tokens.