keskim. murtaminen offline-GPU:lla ≈ 10^11 years
(Dokumentaatio englanniksi)
What it does
Generates cryptographically-random passwords using the Web Crypto CSPRNG (crypto.getRandomValues) with rejection sampling, so every character is drawn uniformly from your selected charset - no modulo bias, no predictable shortcuts. Each draw is independent and happens entirely in your browser.
For every password it shows live entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.length × log₂(charset)) and classifies it into one of five tiers - very weak, weak, fair, strong, very strong - on a 5-segment meter. Under the meter sits the headline number: the average time to crack the password against an offline GPU attack (10¹⁰ guesses/second), computed as 2^(bits−1) / rate - the expected time, i.e. half the keyspace.
Flip Pro to reveal the analytics layer: the
entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
formula broken out (length × log₂(charset) = N bits), a crack-time-vs-length curve plotted for the offline-GPU scenario, and a four-row attack table that spans online-throttled (100/h) up through offline fast-GPU (10¹⁰/s).
How to use it
- Set Length with the slider (4-64 characters; tick marks at 8, 16, 24, 32, 48, 64).
- Toggle the character sets you want:
A-Z,a-z,0-9,!@#(symbols). At least one must be on. - Optionally toggle no O0Il1 to strip visually-ambiguous characters (
O,0,I,l,1) from the pool. - Tap New for a fresh draw, or Copy to copy the current password.
- Read the strength meter and the average offline-GPU crack time below it.
- Flip Pro for the
entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
formula, the crack-time-vs-length curve, and the 4-scenario attack table.
Examples
EntropyEntropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
islength × log₂(charset). The four character sets total 88 characters (26 lower + 26 upper + 10 digits + 26 symbols).
- 16 chars, A-Z + a-z + 0-9 (charset 62):
16 × log₂(62) ≈ 95.3 bits→ strong (4 / 5 segments). Average offline-GPU crack time ≈2^94 / 10¹⁰ ≈ 1.98 × 10¹⁸ s ≈ 6.3 × 10¹⁰ years- the tool displays this as10^11 years. - 16 chars, all four sets incl. symbols (charset 88):
16 × log₂(88) ≈ 103.4 bits→ very strong (5 / 5 segments). - 8 chars, lowercase only (charset 26):
8 × log₂(26) ≈ 37.6 bits→ weak (2 / 5 segments). - Pro scenario spread at 95 bits (average time,
2^94 / rate): online throttled (100/h) →10^22 years; online no-throttle (10/s) →10^20 years; offline slowhashhashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
(10⁴/s) →10^17 years; offline fast GPU (10¹⁰/s) →10^11 years.
Good to know
- Private by design: generation uses
crypto.getRandomValueslocally - the password never leaves your browser, and Pro mode is pure math (no network). - No modulo bias: each character index is drawn via rejection sampling against the largest multiple of the charset size fitting in the 2³² Uint32 range, then reduced - never
random % charset.length. - Average, not worst-case: crack times are the expected time (
2^(bits−1) / rate- half the keyspace). A lucky attacker could finish sooner; a full-keyspace sweep would take roughly twice as long. - Theoretical
entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
: the score assumes a uniform-random draw, which the CSPRNG guarantees. For human-chosen or reused passwords, use the Password Strength Analyser (zxcvbn) - it catches dictionary words, substitutions, and patterns that rawentropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
misses. - Five tiers: very weak (< 28 bits), weak (28-44), fair (45-69), strong (70-99), very strong (≥ 100).
- Shareable: length, character-set toggles, the
no O0Il1flag, and the Pro switch are encoded in the URL (?len=…&upper=1&pro=1…), so a link reproduces the exact configuration. - Related tools: Password Strength Analyser, Token Generator.