Time to Hack: smart password strength & crack time analyzer
v0.0.1 Updated May 5, 2025 4.96MiB
Description
# Time to Hack π
Most websites suck at telling you if your password is actually secure. They are still stuck in the 2000s, using outdated password rules. They check for symbols, numbers, uppercase lettersβthen rate `Password1!` as βstrongβ. But any real attacker cracks that in minutes.
I got tired of these outdated rules that donβt reflect actual security. So I built **Time To Hack**. This Chrome extension estimates how long it would actually take to crack your password (as you type), across realistic attack scenarios using entropy analysis, pattern recognition, and modern cracking models.
## Why Traditional Rules Fail?
Composition-based rules (e.g., one number, one symbol) often lead to predictable formats:
- Capitalized first letter
- Year appended at the end
- `!` or `123` as a suffix
- `p@ssw0rd` - style substitutions
Attackers know these tricks. Tools like `Hashcat` are trained on these patterns. So `Password1!` is still toast in minutes if stored insecurely.
## What This Extension Does
Whenever you type a password on any site:
- Estimates crack time under 3 real-world attack models
- Checks against common patterns from breached passwords & highlights weaknesses using dictionary, keyboard, and pattern analysis
- Finds substitutions and sequences like `qwerty`, `asdf`, `1111`, etc.
- Calculates effective entropy (in bits, not gut feeling) using `zxcvbn` logic
- Shows actual crack time in seconds, days, or centuries
- Gives real suggestions to strengthen it
## How It Works (Under the Hood)
- **Pattern Detection**: Identifies dictionary words, substitutions, sequences (asdf, qwerty, etc.)
- **Entropy Calculation**: Assigns bit-level randomness to patterns, computes guess count
- **Time Estimation**: `Crack Time = Guesses / Attack Speed`
- **Scoring**: Uses `zxcvbn` under the hood, with custom enhancements for better UI and clarity
The core logic comes from Dropbox's [zxcvbn](https://github.com/dropbox/zxcvbn) library. But itβs not just a rule-based checker. Itβs trained on:
- Breached password datasets
- Human typing patterns
- Keyboard layout guesses
- Name + year combos, movie quotes, dictionary words
- Smart transformations (like `p@55w0rd`)
It calculates pattern-based entropy, not random guessing space. So it knows that `Dragon@123` is not strong, even if it βlooksβ complex.
## Attack Models Simulated
| Scenario | Speed | Context |
| ------------------- | ----------------- | -------------------------- |
| Online Rate-Limited | 100 attempts/hour | Login page with throttling |
| Offline (Slow Hash) | 10K guesses/sec | Breach + bcrypt/PBKDF2 |
| Offline (Fast Hash) | 10B guesses/sec | Breach + MD5/SHA1 |
## Examples
| Password | Traditional Verdict | Real Crack Time (Offline Fast) |
| -------------------------- | ------------------- | ------------------------------ |
| `Password1!` | Strong | 3 hours |
| `p@ssw0rd` | Strong | 19 minutes |
| `blueberry pancakes` | Weak | 89 years |
| `correct horse battery...` | Weak | Centuries |
## Built with β€οΈ by
[Pankaj Tanwar](https://twitter.com/the2ndfloorguy), and checkout his [other side-hustles](https://pankajtanwar.in/side-hustles)
## Contributing
I welcome contributions to the `time-to-hack` project! Whether it's a bug fix, a feature request, or improving documentation, your contributions are appreciated.
Reviews
Loading reviews...
Permissions (2)
Permissions
activeTabβΉ Can access the current tab when you click the extension storageβΉ Can store data locally in your browser
Details
| Version | 0.0.1 |
| Updated | May 5, 2025 |
| Size | 4.96MiB |
| First Seen | Mar 24, 2026 |
More by Pankaj Tanwar
IMDBuddy - IMDb Ratings for Hotstar, Netflix, Prime Video & More
by Pankaj Tanwar
681
β
4.89
functionality
681
β
4.89
functionality
Scream to Unlock: yell to unblock social media
by Pankaj Tanwar
196
β
4.00
tools
196
β
4.00
tools
Boeing Flight Detector
by Pankaj Tanwar
138
β
2.33
developer
138
β
2.33
developer
Cringe Guard: filter out cringe content on your LinkedIn feed using AI
by Pankaj Tanwar
114
β
5.00
tools
114
β
5.00
tools
The Real Dark Mode - Your cursor is the flashlight
by Pankaj Tanwar
49
β
0.00
tools
49
β
0.00
tools
Popular in developer
GoFullPage - Full Page Screen Capture
by GoFullPage
10M
β
4.89
developer
10M
β
4.89
developer
TouchEn PC보μ νμ₯
by λΌμ¨μνμ΄
8M
β
1.33
developer
8M
β
1.33
developer
React Developer Tools
by Meta
5M
β
3.95
developer
5M
β
3.95
developer
Meta Pixel Helper
by Meta
4M
β
3.91
developer
4M
β
3.91
developer
ColorZilla
by colorzilla.com
4M
β
4.59
developer
4M
β
4.59
developer
Popular Extensions
Adobe Acrobat: PDF edit, convert, sign tools
by Adobe Inc.
331M
β
4.40
workflow
331M
β
4.40
workflow
AdBlock β block ads across the web
by AdBlock
62M
β
4.48
workflow
62M
β
4.48
workflow
θΏ
ι·δΈθ½½ζ―ζ
by Shenzhen Xunlei Network Technology Co., Ltd.
59M
β
2.77
workflow
59M
β
2.77
workflow
Grammarly: AI Writing Assistant and Grammar Checker App
by Grammarly
42M
β
4.50
communication
42M
β
4.50
communication
Adblock Plus - free ad blocker
by eyeo GmbH
41M
β
4.39
workflow
41M
β
4.39
workflow