Passphrase strength

See how long a secret holds up

HeirVault stretches your passphrase with Argon2id so each offline try is expensive. Compare short secrets with longer phrases below. Teaching tools only. Not a vault score.

Passphrase builder

Every word multiplies the work

1 word
riverlanternquietsixty

One high-end GPU vs our KDF

under a second

Same estimator as the lab below. Random words, not a quote or a date.

Two speeds

A home machine and a high-end GPU

Same Argon2id-class protection (about 64 MB memory cost). Different hardware, different pace. Far slower than a fast login hash.

Try pace

Same secret, two speeds

  • Everyday computer

    Home PC with Argon2id

    Steady pace

  • Dedicated GPU

    High-end GPU with Argon2id

    Faster pace

Everyday computer

About 400 tries per second

A capable home PC or mid-range GPU. Middle ground between a basic laptop and flagship hardware.

Dedicated GPU

About 1,700 tries per second

Roughly one high-end consumer GPU against the same slow, memory-hard settings.

How to read the times

Common patterns first, then the long tail

Offline tools work through known passwords, patterns, and short variants before they reach a long unique phrase. That order is why length helps so much.

Familiar secrets first

Common passwords and published patterns get tried early. A short everyday password often falls for that reason alone.

Symbols rarely save a short base

Swapping letters for symbols on a short base (like P@ssw0rd1) barely helps. Those variants already sit in the early lists.

Anchors, not guarantees

The rates and lab times are teaching anchors from public GPU benchmarks for similar Argon2id settings. Real hardware and software vary.

Lab

Compare a few secrets

Tap an example, or type your own.

Runs only in this browser. Nothing you type is sent to us.

Examples

Everyday computer

~400 tries/s with Argon2id

under a second

Dedicated GPU

~1,700 tries/s with Argon2id

under a second

HeirVault vault passphrases need at least 12 characters. Times assume protection close to our Argon2id settings.

What helps

Length and uniqueness do the work

Argon2id sets the cost of each try. Your secret sets how many tries it takes.

  • Prefer several unrelated words, or one long unique string.
  • Reuse nowhere else. A strong phrase shared across sites loses its edge.
  • Skip short bases with a few symbols. That pattern is already in the early lists.
  • Keep the phrase private. Strength works best when only you hold it.

Honest limits

What this page is for

A local teaching lab

Nothing here runs against your vault or our servers. The lab stays on your device.

Relative strength, not a grade

Results compare secrets under fixed rate anchors. They are not a certification of your account.

One slice of the model

End-to-end encryption, OPAQUE sign-in, and release rules live on Passphrases and Security. This page covers offline try cost.

Want the trust model next?

See how HeirVault protects your live vault with end-to-end encryption, and why your passphrase stays on your side. Or read the full security page.