Crack time calculator / 16 characters
How long to crack a 16-character password
One GPU, fast hash: about 10¹³ years
A truly random 16-character password using letters, numbers and symbols takes about about 10¹³ years to brute-force when a leaked database uses a fast hash like MD5 (one high-end GPU, ~100 billion guesses a second), 118 billion years for a 100-GPU cluster, and about 10²⁰ years if the site used bcrypt. With lowercase letters only, one GPU needs 14 thousand years.
Worst case for a randomly generated password. Check a password you made up yourself with the strength checker.
16-character password crack time table
Time to try every combination of 16 random characters. Rates are round orders of magnitude (see the calculator for where they come from).
| Characters used | Entropy | Rate-limited login 100 guesses/hour | Leaked bcrypt hash ~10,000 guesses/s | Leaked MD5/NTLM, 1 GPU ~100 billion guesses/s | MD5, 100-GPU cluster ~10 trillion guesses/s |
|---|---|---|---|---|---|
| Numbers only (10) | 53 bits | 11 billion years | 32 thousand years | 1.2 days | 17 minutes |
| Lowercase only (26) | 75 bits | about 10¹⁶ years | 138 billion years | 14 thousand years | 1.4 centuries |
| Upper + lowercase (52) | 91 bits | about 10²¹ years | about 10¹⁵ years | 906 million years | 9.1 million years |
| Letters + numbers (62) | 95 bits | longer than the universe will exist | about 10¹⁷ years | 15 billion years | 151 million years |
| Letters, numbers + symbols (94) | 105 bits | longer than the universe will exist | about 10²⁰ years | about 10¹³ years | 118 billion years |
Numbers only, 16 digits, on one GPU against MD5: 1.2 days. Red: under a month. Amber: under a thousand years. Green: longer.
Generate a random 16-character password
Made on your device with crypto.getRandomValues; never sent. More options on the password generator.
Other lengths
- 6 characters6.9 seconds
- 8 characters17 hours
- 10 characters17 years
- 12 characters151 thousand years
- 14 characters1.3 billion years
- 20 charactersabout 10²⁰ years
All symbols, one GPU, fast hash. Each extra character multiplies the work by 94.
16-character password FAQ
How long does it take to crack a 16-character password?
A truly random 16-character password using letters, numbers and symbols takes about about 10¹³ years to brute-force when a leaked database uses a fast hash like MD5 (one high-end GPU, ~100 billion guesses a second), 118 billion years for a 100-GPU cluster, and about 10²⁰ years if the site used bcrypt. With lowercase letters only, one GPU needs 14 thousand years. Human-chosen passwords of the same length usually fall far sooner, because attackers try leaked passwords, words and patterns before brute force.
Is a 16-character password secure?
A random 16-character password from all 94 printable characters has about 105 bits of entropy and is strong when it is generated randomly. That meets the 15-character minimum NIST SP 800-63B recommends when a password is the only factor.
How many 16-character passwords are possible?
With all 94 printable ASCII characters there are 94^16 ≈ 3.7 × 10³¹ combinations. With lowercase letters only, 26^16 ≈ 4.4 × 10²²; with digits only, 10^16 ≈ 1.0 × 10¹⁶.
What does a strong 16-character password look like?
One generated at random, with no words, names, dates or keyboard runs, and used on only one site. The generator on this page makes one in your browser with crypto.getRandomValues. If you need to remember it, a 5–6 word passphrase is easier and usually stronger.