Cyber security · Interactive model

The Password Cracking Rig

Type a candidate password and watch a simulated attacker's GPU rig estimate how long it would survive an offline attack. Crank the attacker's hardware, then try the breach-list toggle — and discover why length beats cleverness, and reuse beats everything.

🔒 Everything runs in your browser. Nothing you type is sent, stored, or logged — but as a habit, don't test your real passwords in any website, including this one.

estimated time to crack

instantcenturies

Start typing to power up the rig.

How the rig sees it
Why length wins: each extra character multiplies the search space by the whole alphabet size. Four random words beat 8 characters of symbol soup.
Why "clever" fails: P@ssw0rd-style substitutions are in every cracking dictionary's rulebook — attackers try them automatically.
The real fix: a password manager generating long unique passwords per site, plus MFA. Then a breach of one site stays a breach of one site.