Password Strength Checker: How Long to Crack + Breach Check
Password strength and breach checker
Your password is never sent anywhere. The strength estimate runs in your browser; the breach check sends only the first 5 characters of its SHA-1 hash to Have I Been Pwned (k-anonymity) and compares the results on this page. Estimates are indicative, not a guarantee.
Type a password into the checker above. Nothing you type is sent to this site or stored anywhere: the strength estimate runs in your browser, and the breach check uses a privacy-preserving lookup explained below.
What the checker measures
- Length and character variety. Each extra character multiplies the number of possible passwords; length helps far more than swapping a letter for a symbol.
- Predictable patterns. Common passwords, keyboard runs (
qwerty,123), repeated characters and years cut the real search space, so the estimate subtracts for them. - Breaches. A password that already appears in a breach can be tried first by attackers no matter how complex it looks, so a breach hit overrides a good strength score.
The guessing times assume an offline attack at 10 billion guesses per second (a stolen database with a fast hash) and an online attack at 100 guesses per second (a login page without lockout). Real attacks use word lists and rules, so treat the numbers as an upper bound for random-looking passwords and a generous one for anything else.
How the breach check keeps your password private
The checker computes the SHA-1 hash of your password in the browser and sends only its first five hexadecimal characters to Have I Been Pwned’s Pwned Passwords service. The service returns every breached hash that starts with those five characters (usually around 2,000 of them) and the checker looks for yours locally. This is called k-anonymity: the service never learns which password, or even which full hash, you checked.
What to do if a password is weak or breached
- Change it everywhere you used it, starting with email and banking.
- Use a different password for every account. A password manager makes that practical.
- Prefer long passphrases of several unrelated words over short complex strings.
- Turn on multi-factor authentication where it is offered.
Sources
- National Institute of Standards and Technology, Digital Identity Guidelines, SP 800-63B (length over forced complexity; screen new passwords against breached-password lists): pages.nist.gov/800-63-4.
- Have I Been Pwned, Pwned Passwords and the k-anonymity range API: haveibeenpwned.com/Passwords.
P.S. A few readers have asked which energy & utilities we actually reach for — it's Direct Energy; if you want the current details.
See plans in your ZIP code
Electricity and natural-gas plans for readers shopping around on energy bills.