Crack time calculator / 8 characters

How long to crack an 8-character password

One GPU, fast hash: 17 hours

A truly random 8-character password using letters, numbers and symbols takes about 17 hours to brute-force when a leaked database uses a fast hash like MD5 (one high-end GPU, ~100 billion guesses a second), 10 minutes for a 100-GPU cluster, and 19 thousand years if the site used bcrypt. With lowercase letters only, one GPU needs 2.1 seconds.

Worst case for a randomly generated password. Check a password you made up yourself with the strength checker.

8-character password crack time table

Time to try every combination of 8 random characters. Rates are round orders of magnitude (see the calculator for where they come from).

Characters usedEntropyRate-limited login
100 guesses/hour
Leaked bcrypt hash
~10,000 guesses/s
Leaked MD5/NTLM, 1 GPU
~100 billion guesses/s
MD5, 100-GPU cluster
~10 trillion guesses/s
Numbers only (10)27 bits1.1 centuries2.8 hoursunder a secondunder a second
Lowercase only (26)38 bits238 thousand years7.9 months2.1 secondsunder a second
Upper + lowercase (52)46 bits61 million years1.7 centuries8.9 minutes5.3 seconds
Letters + numbers (62)48 bits249 million years6.9 centuries36 minutes22 seconds
Letters, numbers + symbols (94)52 bits7 billion years19 thousand years17 hours10 minutes

Numbers only, 8 digits, on one GPU against MD5: under a second. Red: under a month. Amber: under a thousand years. Green: longer.

Generate a random 8-character password

…

Made on your device with crypto.getRandomValues; never sent. More options on the password generator.

Other lengths

All symbols, one GPU, fast hash. Each extra character multiplies the work by 94.

8-character password FAQ

How long does it take to crack an 8-character password?

A truly random 8-character password using letters, numbers and symbols takes about 17 hours to brute-force when a leaked database uses a fast hash like MD5 (one high-end GPU, ~100 billion guesses a second), 10 minutes for a 100-GPU cluster, and 19 thousand years if the site used bcrypt. With lowercase letters only, one GPU needs 2.1 seconds. Human-chosen passwords of the same length usually fall far sooner, because attackers try leaked passwords, words and patterns before brute force.

Is an 8-character password secure?

An random 8-character password from all 94 printable characters has about 52 bits of entropy and is not safe against an offline attack, even when fully random. NIST SP 800-63B recommends at least 15 characters when a password is the only factor, so go longer for important accounts or add two-factor authentication.

How many 8-character passwords are possible?

With all 94 printable ASCII characters there are 94^8 ≈ 6.1 × 10¹⁵ combinations. With lowercase letters only, 26^8 ≈ 2.1 × 10¹¹; with digits only, 10^8 ≈ 1.0 × 10⁸.

What does a strong 8-character password look like?

One generated at random, with no words, names, dates or keyboard runs, and used on only one site. The generator on this page makes one in your browser with crypto.getRandomValues. If you need to remember it, a 5–6 word passphrase is easier and usually stronger.