Back to the tool

How Long Would It Take to Crack Your Passphrase? The Answer Hinges on One Assumption

How long does it take to crack a passphrase? The tables floating around the internet give tidy answers: a 4-word passphrase lasts centuries, a 6-word one millions of years. Those numbers are real arithmetic, but they quietly assume the attacker knows nothing about how you built it. Change that assumption and the answer changes by a factor of millions.

Crack-time estimates all describe the same scenario: someone stole a password database, took the hashes home, and is guessing offline at billions of attempts per second. That is a realistic threat for old breaches hashed with something fast like MD5. It is not what happens when someone types guesses into a login form, which rate-limits and locks out. Keep that scenario in mind. Everything below assumes the offline case, because that is the case these tables measure.

The math with the secret scheme

Take a 4-word passphrase drawn from the EFF diceware long wordlist, which has 7,776 words. Each word carries about 12.9 bits of entropy, so four words give roughly 51.6 bits. The total space is 7,776 to the 4th power, about 3.66 quadrillion combinations.

If an attacker knows you used four diceware words, and guesses at 10 billion per second, a rate several published estimates use for serious hardware, the math is unforgiving: 3.66 quadrillion divided by 10 billion is about 365,000 seconds. That is roughly 4 days, not the centuries the optimistic tables promise.

Now add words. Five diceware words at the same guess rate take about 90 years. Six words take around 700,000 years. Seven words land in the billions of years. Every word multiplies the attacker's work by 7,776, so the jump from four words to six words is the difference between "a long weekend" and "longer than human civilization has existed."

The math without the secret scheme

This is where the centuries come from. Crack-time tables like Hive Systems' 2024 report assume the attacker brute-forces the full character set with no knowledge of your method. Under those assumptions, an 8-character complex password falls in about 7 years against top-end hardware, an 18-character all-numbers password takes 11,000 years, and an 18-character lowercase password takes 350 billion years.

A 4-word passphrase with spaces runs about 27 characters long. An attacker brute-forcing 27 characters from a full character set faces a number so large it stops being a security question and becomes an astronomy question. The optimistic tables are correct, provided the attacker never learns your method.

Here is the catch. Security people have a saying that attackers read the same blog posts you do. Passphrases are mainstream advice now. An attacker targeting you specifically, or just working through a smart wordlist attack, will try word combinations. The pessimistic number is the honest one to plan around.

What I actually take from this

First, four random diceware words are fine against a generic brute-force attack and thin against an attacker who knows your scheme. That is not a comfortable margin. Six random words give roughly 700,000 years of margin even under the pessimistic assumption, and they take about 15 seconds longer to type. I generate six-word passphrases and call it done.

Second, random means random. The math above assumes the words came from dice or a cryptographic generator. Four words you picked because you like them are not 51.6 bits. They are whatever your taste is, and taste is predictable. If you want a passphrase you can both remember and trust, generate it here and write it down once, somewhere safe.

Third, keep the threat in proportion. Most stolen passwords are not brute-forced. They are phished, reused from a breach, or guessed from a leaked list. A strong passphrase protects the brute-force scenario. A password manager protects the reuse scenario, which is the one that actually gets people. Do both.

Frequently asked questions

What does "10 billion guesses per second" actually describe?

An offline attack. The attacker already has the hashed password, usually from a breached database, and is testing guesses on their own hardware with no login page slowing them down. This only applies to hashes. Nobody can guess 10 billion times per second through a website login form.

Why is a 4-word passphrase strong but an 8-character password weak?

It comes down to the size of the search space. Eight characters from a mixed set give around 95 to the 8th power combinations. Four diceware words give 7,776 to the 4th power. Both are "short" secrets, but the word-based one has a vastly larger space because each word is one pick from 7,776 options rather than one pick from 95.

Do attackers really brute-force individual passwords?

Rarely for a specific person. The common real-world attacks are phishing, credential stuffing with passwords leaked from other breaches, and guessing from personal details. Brute force matters mainly at scale, against stolen hash databases. That is why unique passwords per site matter as much as strong ones.

Does adding a symbol or capital letter to my passphrase help?

A little, but far less than adding one more word. A symbol adds a few bits of entropy to each position. A whole new diceware word multiplies the entire space by 7,776. If you want more strength, add a word, not a bang at the end.

How many diceware words do I actually need?

Six, by my reckoning. Six random words give about 77.6 bits of entropy, which stays out of reach even if the attacker knows you used diceware and has serious hardware. Five is defensible. Four is fine against generic attacks but thin against a knowledgeable one, so I no longer recommend stopping there.

Related reading: How Many Words Does Your Passphrase Need? Entropy Math, Worked Out · Diceware Passphrase vs Random Password: Which One Should You Actually Use? · Is It Safe to Use an Online Password Generator? My 60 Second Test · Should You Change Your Passphrase Every 90 Days? What NIST Says Now

Try the tool

The passphrase generator on this site runs entirely in your browser. Nothing is sent anywhere, and you can verify that with the network-tab test above. Generate a passphrase now and watch devtools while you do it.

Get new free tools by email

Want the next guide in your inbox? I publish one practical guide per new tool. Subscribe to the free newsletter on Substack. No spam, unsubscribe anytime.