Best Reviews logo
Best Reviews may receive compensation for its content through paid collaborations. See how we sustain our work & review products.
How Long Does it Take to Crack My Password?

How Long Does it Take to Crack My Password?

By István F.István F. Verified by Adam B.Adam B. Last updated: December 12, 2024 (0)
Table of contents

Do you think you have a strong password? Have you wondered how long it would take a hacker to break into your online accounts or email? It’s easy: there are various sites – such as Randomize, Kaspersky Lab’s secure password check, and LastPass’s password checker – that help analyze the security level of a password. Some of them run locally on your machine without sending data over the internet, others don’t.

The top password managers according to security experts and researchers

But there is a tiny problem with these password security checkers: the time they display is based on calculations for the time it takes to crack the password using a brute-force attack method. That means the attacker systematically checks all possible combinations of six letters and characters, starting with the first letter of the alphabet and ending with ‘//////’.

How do hackers get my password?

Brute force attacks are widely used by hackers to crack passwords, but this is just a part of their toolset. For example, a six-character password using a combination of letters and numbers has just 626 possible combinations (52 letters – both upper case and lower case – plus the 10 numbers, and not counting special characters). In case of an 11-character password using the same formula, that jumps to 6211 combinations. That’s out of reach by brute-force methods, so it’s time to use other techniques such as a dictionary attack or Markov chains.

In a password security experiment set up by Ars Technica, three hackers attempted to crack 16,000+ hashed passcodes, and they managed it with 90% success rate in less than a day: six passwords were cracked every minute including 16-character-long randomly generated passwords such as “qeadzcwrsfxv1331”. Here is how they did it, but first let us explain what a password hash means.

The costs of a data breach for small businesses

The secrets of the password hash

When you enter a password, a one-way mathematical function takes your plain text password and produces a unique string of numbers and letters. That’s called the hash. For example, the “arstechnica” password resulted in the hash “c915e95033e8c69ada58eb784a98b2ed”.

With the hash information to hand, the hackers were able to crack 62% (10,233) of the hashes in 16 minutes. With a mix of a brute-force attack, a hybrid attack that combined a wordlist with brute-force attacks and statistically generated password guesses using Markov chains and other rules, they managed to reverse engineer the hashes into plain text in 15 hours.

The importance of password strength

So what have we learned from this? Keeping in mind the daily occurring digital megabreaches that make millions of password hashes available to the Dark Web, it makes sense to change passwords frequently – as suggested by your password manager of choice.

The Ars Technica experiment, however, also highlighted one important aspect of password security: the longer the password is, the more time and resources a hacker needs to crack it open. For example, if you use a set of seven characters using letters such as “abcdefg”, it can be cracked in milliseconds, but that crack time jumps up to two centuries for brute-force attacks if 12 characters are used like ‘abcdefghijkl’. Not bad for just a few random letters put side by side. The time required for a brute-force attack to crack a password also increases when combining numbers and letters rather than using only letters, and additional tweaks such as combining ASCII, lowercase, uppercase and numeric characters will result in an even stronger password.

60% off RoboForm for Best Reviews readers
RoboForm logo
Commit to RoboForm using Best Reviews' exclusive discount and enjoy a discount of 60% off the regular price.
/goto/roboform/ Click to show code

You decide the security level of the password, but anything below 12 characters can be considered weak, especially in light of this experiment. From that length and upwards you can relax for a while, but that’s also the point at which you will stop remembering passwords due to their complexity. Fortunately, password managers can help with this task, as well as password generation. Still, keep an eye on their security recommendation, and change the passwords for your online accounts regularly.


Best password managers of 2025

Editors' choice
RoboForm logo
Editor's rating:
(4.5)
Effective security center
Passkey compatibility
Intuitive and organized interface
Affordable prices
Families
LastPass logo
Editor's rating:
(4)
Logical interface
Automated password categorization
Advanced mobile version
Various two-factor authentication options
Businesses
1Password logo
Editor's rating:
(4)
End-to-end encryption
Secure authentication method
Data breach alarms
One-time password support
Security features
Keeper logo
Editor's rating:
(4.5)
Robust security
Wide range of platform support
Affordable
Great customer support
Personal use
NordPass Personal logo
Editor's rating:
(4.5)
Strong security features
Effective password generator
Excellent free version
Attractive price
Password sharing
Dashlane logo
Editor's rating:
(4)
Password changer
Built-in VPN
Flawless data import
Thorough iOS/Android app
Local storage
Enpass logo
Editor's rating:
(4)
Packed with features
Free for desktop users
Offline password manager
End-to-end encryption

User feedback

 Leave a reply

Your email address will not be published. Required fields are marked *


Best Reviews

Best Reviews may receive compensation for its content through paid collaborations and/or affiliate links. Learn more about how we sustain our work and review products.

©2012-2025 Best Reviews, a clovio brand – All rights reserved
Privacy policy · Cookie policy · Terms of use · Partnerships · Contact us