Cyber security · Interactive model
The Password Cracking Rig
Type a candidate password and watch a simulated attacker's GPU rig estimate how long it would survive an offline attack. Crank the attacker's hardware, then try the breach-list toggle — and discover why length beats cleverness, and reuse beats everything.
🔒 Everything runs in your browser. Nothing you type is sent, stored, or logged — but as a habit, don't test your real passwords in any website, including this one.
—estimated time to crack
instantcenturies
Start typing to power up the rig.
How the rig sees it
Why length wins: each extra character multiplies the search space by the whole alphabet size. Four random words beat 8 characters of symbol soup.
Why "clever" fails: P@ssw0rd-style substitutions are in every cracking dictionary's rulebook — attackers try them automatically.
The real fix: a password manager generating long unique passwords per site, plus MFA. Then a breach of one site stays a breach of one site.