Text & everyday tools · Password Generator
How password cracking works: hash rates, slow hashing and why entropy wins
· How it works
passwords security threat-models
Explains offline cracking in plain terms — leaked hashes, guesses per second, dictionaries and rules — and how slow hashing algorithms and passphrase entropy together decide whether a password survives.
The breach that leaked hashes, not passwords — what attackers actually obtain and why it is still dangerous
ToolAcre never receives a stored verifier or account database, so it cannot tell whether a destination keeps plaintext, a fast digest or a deliberately expensive password hash. The workbook’s breach narrative may be useful in a separately sourced security article, but it is not established by this generator’s configuration, implementation or tests. This section corrects the heading rather than inventing backend facts.
The local evidence concerns only generation: explicit choice pools, cryptographic bytes, unbiased bounded draws and one returned value. A remote service’s storage architecture can dominate what happens after submission. No amount of browser-side arithmetic lets ToolAcre certify that unseen system, and no generated value is declared suitable for every service.
A generator cannot establish how a remote service stores a password
Online and offline guessing describe different operational conditions, yet their rates depend on controls that are absent from this repository. The page cannot observe login throttling, account lockout, hardware, parallelism or access to a stolen verifier. Publishing a guesses-per-second figure as if it applied universally would turn an illustrative assumption into a false prediction.
The limitations page is explicit that search-time wording rests on a stated assumed rate and changes by orders of magnitude when that assumption changes. For this article, the durable comparison is the number of possible outputs under verified generator settings. Time enters only after external evidence supplies a rate and attack model.
Online and offline attack rates are outside this repository’s verified evidence
The outline names MD5, SHA-1, bcrypt, scrypt and Argon2, but none of their specifications or measured configurations is a source for this module. Algorithm names alone are not enough: parameters, implementations and attacker hardware matter. Rather than cite remembered rankings, this article omits the comparison and tells readers to consult the destination service’s current approved documentation.
That omission is not a gap in the generator. ToolAcre deliberately does not hash, store or verify account credentials. Adding a digest demo would create a second product surface and could encourage readers to treat a toy configuration as deployment advice. The browser page has one job: produce a fresh candidate under transparent settings.
Hash-algorithm comparisons require external sources and are intentionally omitted
Human-choice dictionaries and mangling rules are also external attack models. The source can say that ToolAcre does not choose words by theme, grammar or popularity; it selects uniform indices from the eligible list. It cannot quantify how quickly a particular cracking tool will reach “Summer” plus a year or a substituted symbol without a cited dataset and configuration.
This is why generated and invented strings should not share one entropy label merely because they look alike. ToolAcre calculates the process it runs. A person’s process is unknown and may concentrate heavily on familiar patterns. The safe conclusion is to generate a unique value, not to assign unsupported precision to a human-created example.
Human password dictionaries are outside the generator’s source contract
For N equally likely complete outputs, a full enumeration contains N candidates. ToolAcre can derive N from wordlist size, word count, random case, random delimiters or a character alphabet. Turning N into an average time requires assumptions about ordering and throughput, while turning it into a safety verdict also requires deciding which attacks matter.
The application contains an illustrative search-time function, but its own prose says that those times compare settings and are much less useful as predictions. This article retains the transparent count and drops the universal clock. It also avoids a threshold that would imply one calculated figure is adequate for every threat model.
Search-time figures are assumptions, not predictions or guarantees
A twenty-character random password can be described from the selected ToolAcre alphabet, and a six-word passphrase can be described from the actual filtered word pool. Compute their logarithmic choice counts with those inputs and stop there. Do not attach an invented cracking duration, because neither the target hash nor a measured attack platform is present in the evidence.
The worked comparison must use newly generated private values, not examples printed here. An article output is public by definition. Record only settings and pool counts. The exercise demonstrates why process details matter while preserving the generated credential and avoiding any recommendation to transmit or reuse it.
Worked example: compare generator choice spaces without crack-time claims
Phishing, credential stuffing, malware and keylogging can bypass or reshape the guessing problem. Reuse can expose several accounts after one service fails even if the original generation process had a large choice space. ToolAcre’s limitations page names these failures because a generator cannot repair them.
This article also does not cover recovery workflows, multifactor authentication or password-manager compromise. Those layers deserve system-specific review. Keeping them visible as omissions prevents “more entropy” from becoming a reflexive answer to incidents where the attacker never enumerates the generated space.
The takeaway — you cannot control the site's hashing, but you control entropy, and the Password Generator gives you plenty of it
You control whether a fresh candidate is selected with ToolAcre’s cryptographic, unbiased process. You do not control a third party’s storage simply by choosing that candidate. Treat generation as one input to a wider security design, and obtain evidence for each later layer from the system that owns it.
The Password Generator should not be mistaken for a manager, hash configurator or breach assessor. Its scoped promise is valuable precisely because it is limited: one local value, known settings, no weak random fallback, no history and no transmission by the Generate action.