Crack time calculator / 20 characters

How long to crack a 20-character password

One GPU, fast hash: about 10²⁰ years

A truly random 20-character password using letters, numbers and symbols takes about about 10²⁰ years to brute-force when a leaked database uses a fast hash like MD5 (one high-end GPU, ~100 billion guesses a second), about 10¹⁸ years for a 100-GPU cluster, and longer than the universe will exist if the site used bcrypt. With lowercase letters only, one GPU needs 6.3 billion years.

Worst case for a randomly generated password. Check a password you made up yourself with the strength checker.

20-character password crack time table

Time to try every combination of 20 random characters. Rates are round orders of magnitude (see the calculator for where they come from).

Characters usedEntropyRate-limited login
100 guesses/hour
Leaked bcrypt hash
~10,000 guesses/s
Leaked MD5/NTLM, 1 GPU
~100 billion guesses/s
MD5, 100-GPU cluster
~10 trillion guesses/s
Numbers only (10)66 bitsabout 10¹⁴ years317 million years32 years3.8 months
Lowercase only (26)94 bitsabout 10²² yearsabout 10¹⁶ years6.3 billion years63 million years
Upper + lowercase (52)114 bitslonger than the universe will existlonger than the universe will existabout 10¹⁵ yearsabout 10¹³ years
Letters + numbers (62)119 bitslonger than the universe will existlonger than the universe will existabout 10¹⁷ yearsabout 10¹⁵ years
Letters, numbers + symbols (94)131 bitslonger than the universe will existlonger than the universe will existabout 10²⁰ yearsabout 10¹⁸ years

Numbers only, 20 digits, on one GPU against MD5: 32 years. Red: under a month. Amber: under a thousand years. Green: longer.

Generate a random 20-character password

…

Made on your device with crypto.getRandomValues; never sent. More options on the password generator.

Other lengths

All symbols, one GPU, fast hash. Each extra character multiplies the work by 94.

20-character password FAQ

How long does it take to crack a 20-character password?

A truly random 20-character password using letters, numbers and symbols takes about about 10²⁰ years to brute-force when a leaked database uses a fast hash like MD5 (one high-end GPU, ~100 billion guesses a second), about 10¹⁸ years for a 100-GPU cluster, and longer than the universe will exist if the site used bcrypt. With lowercase letters only, one GPU needs 6.3 billion years. Human-chosen passwords of the same length usually fall far sooner, because attackers try leaked passwords, words and patterns before brute force.

Is a 20-character password secure?

A random 20-character password from all 94 printable characters has about 131 bits of entropy and is strong when it is generated randomly. That meets the 15-character minimum NIST SP 800-63B recommends when a password is the only factor.

How many 20-character passwords are possible?

With all 94 printable ASCII characters there are 94^20 ≈ 2.9 × 10³⁹ combinations. With lowercase letters only, 26^20 ≈ 2.0 × 10²⁸; with digits only, 10^20 ≈ 1.0 × 10²⁰.

What does a strong 20-character password look like?

One generated at random, with no words, names, dates or keyboard runs, and used on only one site. The generator on this page makes one in your browser with crypto.getRandomValues. If you need to remember it, a 5–6 word passphrase is easier and usually stronger.