How Passwords Work

Why "password123" is a terrible idea

1

Your Digital Keys

The average person has 100+ online accounts. Each password is a key to your digital life.

🔑
0
accounts protected by passwords
123456
password
qwerty
abc123
letmein
admin

⚠ These are the most commonly used passwords. Never use them!

🔒 First Line of Defense

Passwords are often the only thing between hackers and your personal data, money, and identity.

📈 81% of Breaches

Weak or stolen passwords are responsible for over 80% of data breaches according to Verizon's research.

2

The Brute Force Attack

Hackers try every possible combination. See how fast different passwords can be cracked.

6
Character Pool: 26
Possible Combinations: 308,915,776
~5 seconds
at 10 billion guesses/second
⚡ Speed Fact

Modern GPUs can test 100 billion password combinations per second. A 6-character lowercase password? Cracked instantly.

3

Entropy: Measuring Randomness

Password strength is measured in "bits of entropy" - more bits = exponentially harder to crack.

Password Comparison
abc123 ~28 bits - Instant
P@ssw0rd! ~42 bits - 2 hours
correct horse ~44 bits - 8 hours
Tr0ub4dor&3 ~52 bits - 3 days
correcthorsebatterystaple ~77 bits - 550 million years
Key Insight: Four random common words beat a complex short password!

📊 The Math

Entropy = log₂(poolⁿ). Each bit doubles the difficulty. 77 bits has 2⁷⁷ combinations!

💡 XKCD Wisdom

"Through 20 years of effort, we've trained everyone to use passwords hard for humans to remember but easy for computers to guess."

4

Hashing: Your Password's Disguise

Good websites never store your actual password. They store a "hash" - a one-way fingerprint.

SHA-256 Hash
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
⚠ Even a tiny change creates a completely different hash!

✔ One-Way Function

You can turn a password into a hash, but you can't turn a hash back into a password. That's the magic!

🔍 Login Process

When you log in, the site hashes what you typed and compares it to the stored hash. Match = you're in!

5

Salting: Defeating Rainbow Tables

Hackers pre-compute hashes for common passwords. "Salting" defeats this attack.

Password: "password"
Salt: a7f3b2c1
Combined: "passworda7f3b2c1"
Hash: 3a7bd3e2...
Same password + different salt = completely different hash every time!

🌈 Rainbow Tables

Hackers pre-compute millions of password hashes. Without salt, "password" always hashes to the same thing.

🧂 Salt Defeats This

A unique random salt for each user means hackers can't use pre-computed tables. They must crack each hash individually.

6

Test Your Password

See how strong your password really is. (Don't use your real passwords!)

Type a password to test
Entropy
0 bits
Crack Time
Instant
Checks
💡 Pro Tips

Use a password manager to generate and store unique passwords. Enable two-factor authentication everywhere you can!

Password Pro!

You now understand why strong, unique passwords are your first line of defense online.

0
Passwords Tested
0
Hashes Seen
0
Time Exploring

Length > Complexity

A longer password is exponentially harder to crack than a short complex one.

Never Plain Text

Good websites store hashed passwords, not your actual password.

Unique is Key

Reusing passwords means one breach can compromise all your accounts.

Entropy Matters

Password strength is measured in bits of entropy - more randomness = more secure.

Ready to Create?

Put your new knowledge into practice!

Suggest a Correction