All posts

#strong password#cybersecurity#password security

What Makes a Strong Password? Will Yours Fall in 3 Seconds or 132 Years?

A random 8-character password holds for 132 years, a predictable one falls in 3 seconds. 2026 data, the new NIST rules and the formula for a truly strong password.

What Makes a Strong Password? Will Yours Fall in 3 Seconds or 132 Years?
Contents 9

A strong password is very different from what most of us think. According to Hive Systems' 2026 measurements, a randomly generated 8-character mixed password can take up to 132 years to crack; yet a password of the same length written with a predictable pattern, or one that has leaked before, falls in about 3 seconds on a single graphics card. What makes the difference is not symbols, but randomness and length.

In short:

  • Attackers do not try your password on the login page; they take a leaked database to their own machines and make hundreds of thousands of guesses per second.
  • Eight random lowercase letters fall in about 17 days, a random 8-character mixed password in at most 132 years, and a predictable password in about 3 seconds.
  • The US standards body NIST now requires at least 15 characters and forbids "must include uppercase, digit, symbol" rules and periodic password changes.
  • The safest setup is a password manager, two-factor authentication and passkeys wherever possible.

"My account locks after 5 wrong attempts, how can it be cracked?"

This is the most common misconception about passwords. The attempt limit on a login screen only protects the live website. The real danger starts when a site's database leaks.

Sites do not store your password as plain text but as a hash, a one-way fingerprint. For example, the MD5 hash of "password" is always 5f4dcc3b5aa765d61d8327deb882cf99. You cannot go back from the hash to the password; but an attacker can hash billions of candidate passwords and compare them with the stolen list. This is password cracking, and it happens entirely offline: no lockout, no warning e-mail, no time limit.

As Hive Systems puts it, an attacker does not need to beat your login page, they only need to wait. So the question that matters is: when the database leaks, how long does your password hold?

How powerful is an attacker in 2026?

Every year Hive Systems publishes a password cracking table based on the most powerful hardware an ordinary attacker can rent. The 2026 table assumes:

  • Hardware: 16 NVIDIA RTX 5090 gaming cards across two rented cloud servers.
  • Hash: bcrypt with a work factor of 10 (each guess is hashed 1,024 times), one of the most common choices in web applications.
  • Speed: about 138,675 guesses per second.

An interesting detail: $30,000 AI accelerators are no better than gaming cards at cracking passwords. Hive measured that eight A100 cards need about 52 years to crack an 8-character password of upper- and lowercase letters, while eight RTX 5090s finish the same job in 23 years. Cracking needs plain integer math; AI chips are designed for a completely different kind of maths.

Hardware gets faster every year. The maximum time to crack the same random 8-character mixed password has almost halved in three years:

Random 8-character mixed password, maximum time to crack (years)
2024225 years
2025164 years
2026132 years

Kaynak: Hive Systems Password Table

How fast can your password be cracked?

The times below are the maximum times needed to try every possible combination at the 138,675 guesses per second Hive measured in 2026. An average attack succeeds in half that time.

Password type Possible combinations Maximum time
8 digits (like a PIN) 100 million about 12 minutes
8 random lowercase letters 209 billion about 17 days
8 random characters (upper, lower, digits, symbols) 576 trillion about 132 years
12 random lowercase letters 95 quadrillion about 22 thousand years
15 random lowercase letters 1.7 sextillion about 380 million years
Any predictable or previously leaked password in the wordlist about 3 seconds

The most important row is the last one. Hive measured this scenario on real hardware in 2026: a single RTX 5090 found a predictable bcrypt-protected password in about three seconds when the attacker tried likely guesses first. Real attackers never start from scratch. They start with lists of billions of leaked passwords, dictionary words and human patterns like "Liverpool1892!" or "Summer2026*".

In other words: the hundreds of years above only apply to truly random passwords. A password you made up yourself, however complex it looks, is probably not random.

Length beats complexity

The numbers in the table reveal a surprising fact. An 8-character password with symbols and digits holds for 132 years; but a random 15-character password made only of lowercase letters has about 3 million times more combinations.

The reason is simple maths. Each new character multiplies the number of combinations by the size of the character set. Growing the set from 26 letters to 70 characters makes each character about 2.7 times stronger, while adding one more character makes the password at least 26 times stronger.

That is why passphrases of 5–6 randomly chosen words are both memorable and very strong. Five words chosen at random from the standard 7,776-word Diceware list create a search space of about 6.5 million years on the same hardware. The key is that dice or a program chooses the words, not you.

NIST's new rules: forget the old password advice

The US National Institute of Standards and Technology (NIST), whose digital identity guideline SP 800-63B is a reference for organisations worldwide, fundamentally changed its password rules in the latest revision:

  • Passwords used on their own must be at least 15 characters. For passwords used as part of multi-factor authentication, the minimum is 8.
  • Systems should allow passwords of at least 64 characters and accept spaces and Unicode characters.
  • Composition rules such as "at least one uppercase letter, one digit, one symbol" are forbidden.
  • Users cannot be required to change passwords periodically. A change is mandatory only when there is evidence of compromise.
  • New passwords must be checked against a blocklist of leaked and common passwords.

So company policies that make you switch "Password2026!" to "Password2026?" every three months are now officially outdated. Forcing people to change passwords constantly leads to small, predictable changes, which lowers security instead of raising it.

Will AI or quantum computers crack my password?

The short answer to both: not directly.

AI gives attackers a serious boost in finding vulnerabilities, writing phishing e-mails and managing rented servers. Hive also notes that in 2026, AI-assisted scripting made it easier to assemble a bigger cracking rig. But cracking a deliberately slow hash like bcrypt is a matter of raw throughput, not reasoning. In a study cited by Hive, language models trying to guess passwords scored below 1.5% accuracy.

Quantum computers mainly threaten public-key cryptography such as RSA and elliptic curves. Against password hashes, the best known quantum method (Grover's algorithm) only offers a square-root speed-up, which can be offset with longer passwords or stronger settings.

6 practical rules for a strong password

  1. Use a password manager. Bitwarden, 1Password or your browser's built-in manager generates a long random password for every site; you only need to remember one master passphrase.
  2. Choose length: at least 15 characters. If you need to remember it yourself, use a passphrase of 5–6 randomly chosen words.
  3. Never reuse passwords. A leak on one site opens every account that shares the same password.
  4. Turn on two-factor authentication. Prefer an authenticator app or a security key over SMS where possible.
  5. Switch to passkeys. Google, Apple and Microsoft accounts and many large sites now let you sign in with a passkey on your device instead of a password. Passkeys cannot be guessed, leaked from a server or typed into a fake site.
  6. Check for leaks. Have I Been Pwned shows which breaches your e-mail address appears in.

A note for developers too: storing user passwords with a slow, salted method such as bcrypt, scrypt or Argon2id is what makes the "years" in the table above possible. At EngerekTech we build authentication to these standards in our web and enterprise software projects.

Frequently asked questions

How many characters should a strong password have?

According to NIST's current guideline, a password used on its own should have at least 15 characters. If you use a password manager, random passwords of 20 characters or more cost you no extra effort.

Should I change my password regularly?

No, not unless there is a leak or something suspicious. NIST no longer recommends periodic password changes because they push people towards small, predictable variations. When you hear about a breach, change it right away.

Don't symbols and uppercase letters make a password stronger?

In a randomly generated password they do, but not as much as length. Symbols people add themselves usually sit in predictable places (a "!" at the end or "@" instead of "a"), and cracking tools try those patterns first.

What is a passkey, and is it safer than a password?

A passkey is a digital key stored on your device and unlocked with your fingerprint, face or screen lock. Since no crackable password is stored on the server and it cannot be handed to a fake site, it is far safer than a password against phishing and database leaks.

Sources

ShareLinkedInXWhatsApp
Need help with this?

If you would like to apply what this post covers to your own project, let’s look at it together.

Write to us
YE

Founder of EngerekTech. Builds web, mobile and enterprise software for businesses with Angular, Spring Boot and Flutter, and made the KPSS Düello and Kelime Kavanozu apps. On the blog he covers AI tools and software development as he uses them in his own projects.