MEG Team ToolsPractical tools. In your browser.All tools

Password Compare

One extra character. A much bigger search.
Explore two passwords and see the difference in real-world time.

Analysis stays in this browser.
No uploads. No saved passwords.

Detail level

Use made-up examples, not passwords you rely on.

Illustrative rates, not benchmarks. Actual speed depends on the service, hardware and password hashing.

The comparison

Enter two examples to see how their search spaces compare.

These times describe an exhaustive search, not a prediction of when a password will be cracked.

Try a comparison

Examples are public teaching material. Do not use them as real passwords.

What if an attacker spots a pattern?

Secondary estimate

Attackers try common words, repeats, dates and keyboard sequences before every possible combination. A huge search space can still contain an easy guess.

Password A

Enter an example to check for recognisable patterns.

Password B

Enter an example to check for recognisable patterns.

An estimate, not a verdict. Pattern-based estimates are not definitive. A large brute-force search space does not guarantee a strong password, and attackers may guess predictable patterns much sooner. No pattern detected does not mean a password is safe.

Read the numbers with the right context

Length expands the possibilities

Each extra character multiplies the combinations at that length by the alphabet size. A wider character mix increases that alphabet. This describes possibilities, not how randomly a person chose their password.

Centuries are a model, not a promise

The calculator asks how long it takes to try every combination up to this length. A guess can succeed much earlier. If the target were uniformly random across that whole space, the average would be about half the displayed time.

Online and offline are different

A sign-in service can slow or block repeated attempts. With stolen password hashes, attackers can work offline; the hashing algorithm and its settings make a large difference to their speed.

Use the lesson beyond this page

Choose long, unique passwords with a password manager, or a passphrase made from randomly selected words. Predictable padding and familiar quotations are not substitutes for unpredictability. Enable MFA or use passkeys where available.

How the calculation works, and its limits

Inspired by GRC’s Password Haystacks. Our independently implemented calculator counts every string from length 1 to your example’s length using the detected alphabet. It does not copy GRC’s password recommendations.

S = R + R² + … + Rᴸ, where R is the alphabet size and L is the length. Lowercase adds 26, uppercase 26, digits 10, and symbols (including space) 33. Symbols use printable ASCII. Spaces are counted exactly, including leading and trailing spaces. Non-ASCII characters and control characters fall outside this model.

The model includes all strings in that alphabet, not just those containing every detected character type. It does not measure entropy or prove randomness. Exhaustive time is S divided by guesses per second. A year is 365.25 days. Displayed durations and ratios are rounded to three significant figures; exact counts appear in Technical mode.

Brute-force calculations support up to 1,024 Unicode code points. Pattern checking uses zxcvbn-ts with English and common dictionaries and is limited to 128 UTF-16 code units to keep the page responsive. Longer inputs are not silently shortened. It cannot know personal context, every language, or whether a password has been exposed. No online breach check is performed.

All scripts and dictionaries are served from this site. Passwords remain in memory and are cleared on reload or leaving the page. We use no analytics, password history, cookies or local storage. For broader guidance, see NIST’s authentication guidance.