Argon2id scenario · 64 MB

Argon2id Password Cracking Calculator

Estimate Argon2id t=3, 64 MB exhaustive search on an H100 and compare it with bcrypt, scrypt, or PBKDF2.

Attack model

Choose a hash family and hardware profile; the table updates immediately.

Maximum time for a complete brute-force search. Human-chosen passwords can be weaker than the same length suggests.
Length 0-9 a-z a-z, A-Z a-z, A-Z, 0-9 a-z, A-Z, 0-9, symbols
> 10 years (Safe)
1–10 years
1 day – 1 year
1 sec – 1 day
< 1 sec (Cracked)
What matters

Length beats complexity

A long random passphrase usually outperforms a short password with symbols. Use a password manager and unique passwords.

Where this applies

Offline hashes only

The model assumes an attacker already has the hash and can test guesses locally. Online logins behave very differently.

For organizations

Prefer slow hashes

bcrypt, Argon2id, scrypt, and high-cost PBKDF2 make every guess expensive and change the table dramatically.

How to read the estimate

Argon2id consumes memory as well as computation, so it scales less efficiently on GPUs than fast hashes. These estimates apply only to the current t=3, 64 MB profile.

Frequently asked questions

Why do Argon2id parameters matter?

Time, memory, and parallelism determine the cost of each guess; another application may use a very different profile.

Is this estimate universal for Argon2id?

No. It applies to the stated t=3, 64 MB profile and selected hardware.

Is Argon2id better than bcrypt?

Both are designed for password storage; Argon2id additionally raises the cost of massive parallel attacks through memory requirements.

Methodology

Scope of Applicability

Assumptions & Limitations

    References