Wi-Fi scenario · WPA/WPA2

WPA2 Password Cracking Time Calculator

Compare random WPA/WPA2 passphrase resistance from eight characters under an offline PMKID model.

Attack model

Choose a hash family and hardware profile; the table updates immediately.

Maximum time for a complete brute-force search. Human-chosen passwords can be weaker than the same length suggests.
Length 0-9 a-z a-z, A-Z a-z, A-Z, 0-9 a-z, A-Z, 0-9, symbols
> 10 years (Safe)
1–10 years
1 day – 1 year
1 sec – 1 day
< 1 sec (Cracked)
What matters

Length beats complexity

A long random passphrase usually outperforms a short password with symbols. Use a password manager and unique passwords.

Where this applies

Offline hashes only

The model assumes an attacker already has the hash and can test guesses locally. Online logins behave very differently.

For organizations

Prefer slow hashes

bcrypt, Argon2id, scrypt, and high-cost PBKDF2 make every guess expensive and change the table dramatically.

How to read the estimate

This page models offline candidate testing after handshake or PMKID material has been obtained. It does not scan networks or crack Wi-Fi; it only estimates the theoretical exhaustive-search space.

Frequently asked questions

Do I enter my network name or password?

No. The service never accepts SSIDs, handshake captures, or real passwords.

Why does the preset start at eight characters?

WPA2-Personal requires a passphrase of at least eight characters.

How is WPA3 different?

WPA3-SAE makes offline guessing harder; a separate WPA3 option is available in the calculator.

Methodology

Scope of Applicability

Assumptions & Limitations

    References