September 13, 2026 · 7 min read

How password crackers actually work

"Cracking a password" sounds like one thing, but it's really four different attacks with different costs, different targets, and different defenses. Knowing which one actually threatens you changes what's worth doing about it.

Online guessing — the slow, loud method

The most obvious attack is typing guesses into a login form. It's also the least effective, because any competent site rate-limits or locks an account after a handful of failed attempts. This is why login forms rarely get "cracked" directly — it's the attack that almost never actually works, and it's not the one you should be optimizing your password against.

Offline brute force — the one that matters

The real threat starts after a database breach. When a site is compromised, attackers don't get plaintext passwords — a properly built site stores a hash, a one-way scramble of the password. But hashing is fast by design in many older systems, and consumer GPU rigs can compute billions of hashes per second with no rate limit and no lockout, because there's no server watching. This is offline brute force: trying every possible combination against the stolen hash until one matches. Here, length is everything — each additional character multiplies the number of combinations an attacker must try, which is exactly what the entropy score on our strength checker is estimating: how many guesses, at a given hardware speed, it would take.

Dictionary attacks — brute force with a head start

Pure brute force is a last resort, because it's rarely necessary. Real-world cracking tools like Hashcat and John the Ripper start with dictionaries — lists of real passwords leaked from previous breaches, the most famous being the 14-million-entry rockyou.txt — and then apply "mangling rules" that append digits, capitalize letters, and substitute characters the way people actually do (summer → Summer2024!). Because so many people build passwords the same predictable way, a dictionary-plus-rules attack cracks the large majority of real-world leaked password sets in minutes, long before pure brute force would be needed. This is why a password that "looks" complex but started life as a word is far weaker than its character count suggests.

Credential stuffing — no cracking required

The most common account takeover method today skips cracking entirely. Attackers take already-cracked or plaintext-leaked email/password pairs from one breach and try them, unmodified, against every other major site's login form. If you reused that password anywhere else, the attacker doesn't need to guess or crack anything — they already have it. This is the strongest argument for a unique password per site, generated with something like our password generator and kept in a password manager: it makes every breach an isolated incident instead of a master key to your other accounts.

Rainbow tables — and why salting killed them

Before GPUs made brute force cheap, attackers used rainbow tables: massive precomputed lookup tables mapping common passwords to their hashes, trading disk space for the time it would take to hash each guess live. The countermeasure is a salt — a random value unique to each password, mixed in before hashing, so the same password produces a different hash on every account. A precomputed table for one salt is useless against another, which is why every modern authentication system salts its hashes and rainbow tables are largely a historical attack today rather than a live one.

What this actually means for you

You can't control how a site stores your password, whether it salts its hashes, or whether it gets breached. You can control two things: how hard your specific password is to guess or crack (long, random, not derived from a real word), and whether a breach of one account exposes any of your others (it shouldn't, if every password is unique). Those two habits defend against all four attacks above at once.