🌐
Bitwarden
bitwarden.com › password-strength
Password Tester | Test Your Password Strength | Bitwarden
A password strength tester instantly provides this information and empowers you to choose the strongest possible password to keep your account information safe. Strong and unique passwords can be automatically generated for free using the Bitwarden ...
🌐
Bitwarden
bitwarden.com › password-security-checker
Password Security Checker: Everything You Need to Know | Bitwarden
Ready to test the strength of your passwords? Try the free and secure · Bitwarden Strength Tester.
Discussions

Bitwarden Password Strength Tester
The other explanations here are true but maybe this will clarify why. Bad password checkers assume a cracking program will guess, in order: a, b, c, … aa, ab, ac, ad, … and so on forever. Good password strength checkers calculate entropy (~randomness) with the assumption of common reasonable wordlists and standard variations on those words, in addition to gibberish character strings. Password cracking tools don’t tend to guess every single random string of characters from shortest to longest, since many people are more likely to choose real words or variations of words. So, for example, “eggplan” is actually a stronger password than “eggplant” despite having fewer characters. They’re both awful, but any decent password cracking tool will guess a word a human is more likely to choose first (vs egg + plan, two unusual words to combine). “eggplan” will even take longer to crack than “eggpl@nt” because a→@ is such a common substitution for humans trying to strengthen their passwords that password cracking tools will likely try it first. Extending to longer sequences, 3-6 memorable unmodified words chosen randomly from very long lists will usually be both more memorable and harder to crack than 2-3 words with symbols inserted. Edit to add: the best way to get a sense of how this works in practice is here: https://lowe.github.io/tryzxcvbn/ More on reddit.com
🌐 r/Bitwarden
97
83
September 19, 2022
Testing my master password - Questions
I am mildly curious as to whether my master password is secure, so I did some reading on the Data Breach report. I say “mildly concerned” because my master PW is well over 16 characters, in addition to having some other characteristics that I believe makes it unique and uncompromised (or ... More on community.bitwarden.com
🌐 community.bitwarden.com
0
March 31, 2024
Password Strength Testing Tool - password from list listed as secure
Don’t use password strength testers… that’s what you missed. They just look for characteristics like length and characters used and aren’t really a good measure of how secure a password is. More on reddit.com
🌐 r/Bitwarden
23
61
September 17, 2024
Password Strength Testing Tool Strangeness
All password "strength" testing tools that work by analyzing a user-entered password example produce invalid results. They are for entertainment purposes only, and should never be relied on to make decisions related to cybersecurity. Bitwarden's tool is no exception. It is based on zxcvbn tool , which is somewhat better than other password testing tools, but can still produce wildly misleading results. In your case, you may have started with something like hge9e3&jg[s19, which the zxcvbn tool cannot match to its inventory of password patterns, so it conservatively estimates that 1013 guesses (a factor of 10× for each character) would be require to crack this password. It also assumes that an attacker would be limited to making 10,000 password guesses per second (which is unrealistic for your laptop password, but could be plausible for your Bitwarden master password). Thus, the cracking time is estimated to be 1 billion seconds, which is 31.7 years. If you now add a digit (e.g., 3) at the end of your password string (hge9e3&jg[s193), then the zxcvbn tool still cannot match the string to any of its password patterns, so it determines the number of required guesses to be 10× higher than before (1014 guesses). Thus, the estimated cracking time is also going to be ten times longer (317 years, a.k.a. "centuries"). If you now add one more digit (e.g., 4) at the end of the previous string (hge9e3&jg[s1934), then something interesting happens. In this case, the zxcvbn tool recognizes the pattern 1934 as a recent calendar year, a pattern commonly found in passwords. The zxcvbn algorithm therefore estimates that it would take at most 90 guesses to come up with the 1934 pattern by working backwards from 2024 (as opposed to its standard estimate of 10,000 guesses for a 4-character sequence with no recognized pattern). Therefore, the password is now parsed as a random 11-character string (hge9e3&jg[s, requiring 1011 guesses) followed by a 4-character year pattern (1934, requiring 90 guesses). The tool then applies a fudge factor of 2×, coming up with 1.8×1013 guesses for cracking this longer password. With an assumed guessing speed of 104 guesses/second, the cracking time ends up being 1.8 billion seconds, corresponding to 57 years. Do all of these assumptions seem arbitrary? They are. Can we trust the results? No. More on reddit.com
🌐 r/Bitwarden
20
16
June 10, 2024
🌐
Bitwarden
bitwarden.com › blog › how strong is my password?
How strong is my password? | Bitwarden
June 20, 2023 - This tool gauges how long it might take to crack your password by testing it against known criteria such as length, randomness, and complexity. Using the password strength tester will give you a quick answer to the question “how strong is ...
🌐
Reddit
reddit.com › r/bitwarden › bitwarden password strength tester
r/Bitwarden on Reddit: Bitwarden Password Strength Tester
September 19, 2022 -

In light of the recent LastPass breech I looked at different strength test websites to see how long a password would hold up under a offline brute-force attack.

The password I tried was: Aband0nedFairgr0und

This is a a 19 character password with a combination of uppercase/lowercase/numbers. Granted, there is no special characters.

I went to 5 different password strength sites and they all give me wildly different results for how long it would take to crack.

https://www.security.org/how-secure-is-my-password/ 9 quadrillion years
https://delinea.com/resources/password-strength-checker 36 quadrillion years
https://password.kaspersky.com/ 4 months
https://bitwarden.com/password-strength/ 1 day

As you can see the results are all over the place!

Why is the Bitwarden result so low and if the attacker had zero knowledge of the password, is it feasible to take an average of the diufferent results and assume that password is sronger that 1 day?

PS: Dont worry, Aband0nedFairgr0und is not a password I use and was made up as a test.

Top answer
1 of 5
63
The other explanations here are true but maybe this will clarify why. Bad password checkers assume a cracking program will guess, in order: a, b, c, … aa, ab, ac, ad, … and so on forever. Good password strength checkers calculate entropy (~randomness) with the assumption of common reasonable wordlists and standard variations on those words, in addition to gibberish character strings. Password cracking tools don’t tend to guess every single random string of characters from shortest to longest, since many people are more likely to choose real words or variations of words. So, for example, “eggplan” is actually a stronger password than “eggplant” despite having fewer characters. They’re both awful, but any decent password cracking tool will guess a word a human is more likely to choose first (vs egg + plan, two unusual words to combine). “eggplan” will even take longer to crack than “eggpl@nt” because a→@ is such a common substitution for humans trying to strengthen their passwords that password cracking tools will likely try it first. Extending to longer sequences, 3-6 memorable unmodified words chosen randomly from very long lists will usually be both more memorable and harder to crack than 2-3 words with symbols inserted. Edit to add: the best way to get a sense of how this works in practice is here: https://lowe.github.io/tryzxcvbn/
2 of 5
33
Bitwarden.com uses zxcvbn to calculate the time-to-crack. You can try it online at https://lowe.github.io/tryzxcvbn/ and it'll tell how it arrived at a time of 1 day.
🌐
Bitwarden
bitwarden.com › how-secure-is-my-password
How Secure is my Password | Bitwarden
Free Password GeneratorPassword Strength Tester ·  · Our daily lives take place increasingly online.

free and open-source password manager

Bitwarden is a freemium open-source password management service that is used to store sensitive information, such as website credentials, in an encrypted vault. It is owned and developed by Bitwarden, Inc. Bitwarden … Wikipedia
Factsheet
Original author Kyle Spearrin
Developer Bitwarden Inc.
Initial release 10 August 2016 (2016-08-10)
Factsheet
Original author Kyle Spearrin
Developer Bitwarden Inc.
Initial release 10 August 2016 (2016-08-10)
🌐
Bitwarden
bitwarden.com
Best Password Manager for Business, Enterprise & Personal | Bitwarden
Bitwarden is the most trusted password manager for passwords and passkeys at home or at work, on any browser or device. Start with a free trial.
🌐
Bitwarden
bitwarden.com › blog › how to test the strength of your passwords in 2022
How to Test the Strength of Your Passwords in 2022 | Bitwarden
For those interested in testing the strength of current passwords, you can do this safely and automatically using the free Bitwarden Password Strength Tester.
🌐
Bitwarden
bitwarden.com › password-generator
Free Password Generator | Create Strong Passwords and Passphrases | Bitwarden
Easy and secure password generator that's completely free and safe to use. Generate strong passwords and passphrases for every online account with the strong Bitwarden password generator, and get the latest best practices on how to maintain ...
Find elsewhere
🌐
Bitwarden
bitwarden.com › passphrase-generator
Secure Passphrase Generator | Generate Secure Passwords | Bitwarden
Need a strong passphrase? Try the Bitwarden Passphrase Generator to create complex passphrases that will keep your information safe. ... Want to test the strength of another passphrase or password?
🌐
Bitwarden
bitwarden.com › blog › the most effective strategy for achieving password strength
The most effective strategy for achieving password strength | Bitwarden
December 26, 2023 - A user could feasibly test each and every one of their passwords to ensure they are meeting the requirements for “strong” or “very strong”. Or, they could use the · Bitwarden Strong Password Generator in conjunction with the Bitwarden Password Strength Testing Tool.
🌐
Bitwarden
bitwarden.com › blog › how to determine your password health
How to determine your password health | Bitwarden
July 5, 2023 - Users who feel relatively confident about the strength of the passwords - and those that do not - can also leverage the Bitwarden password strength testing tool. They can simply type in or copy their password (which is never transmitted to the Bitwarden servers and is processed locally in a device’s web browser window) and be given an evaluation.
🌐
Bitwarden
bitwarden.com › blog › how long should a password be?
How long should a password be? | Bitwarden
You can easily build strong passwords using the Bitwarden Password Generator, a free and secure online tool designed to generate unique passwords for every account with customization options to support any site’s password policies. Additionally, you can test the strength of new or existing credentials with the free Password Strength Tester...
🌐
Bitwarden
bitwarden.com › products › personal
Free Personal Password & Passkey Manager Online | Bitwarden | Bitwarden
Voted #1 by PCMag, The Verge, CNET, and G2. Secure your digital life with the Bitwarden Personal Password Manager. Start a free trial today!
🌐
Chrome Web Store
chromewebstore.google.com › detail › bitwarden-password-manage › nngceckbapebfimnlniiiahkandclblb
Bitwarden Password Manager - Chrome Web Store
Cross-Platform Applications Secure and share sensitive data within your Bitwarden Vault from any browser, mobile device, or desktop OS, and more. Bitwarden secures more than just passwords End-to-end encrypted credential management solutions from Bitwarden empower organizations to secure everything, including developer secrets and passkey experiences.
🌐
Bitwarden
community.bitwarden.com › ask the community › password manager
Testing my master password - Questions - Password Manager - Bitwarden Community Forums
March 31, 2024 - I am mildly curious as to whether my master password is secure, so I did some reading on the Data Breach report. I say “mildly concerned” because my master PW is well over 16 characters, in addition to having some other …
🌐
UIC
uic.edu › apps › strong-password
Password Meter - A visual assessment of password strengths and weaknesses
Disclaimer: This application is designed to assess the strength of password strings. The instantaneous visual feedback provides the user a means to improve the strength of their passwords, with a hard focus on breaking the typical bad habits of faulty password formulation.
🌐
PasswordMonster
passwordmonster.com › home
Password Strength Meter
March 3, 2022 - How strong are your passwords? Test how secure they are using the My1Login Password Strength Test.
🌐
Tech.co
tech.co › home › cybersecurity
How To Test Your Password Strength for Free - Tech.co
January 3, 2024 - Find out precisely how long it'll take a hacker to crack a password as long - and as complex - as yours.
🌐
X
x.com › Bitwarden › status › 1850948162321604728
Bitwarden - X
Put it to the test with the password strength tool: https://btwrdn.com/3YDrO1E #cybersecurityawarenessmonth · 1:10 PM · Oct 28, 2024 · · · 12.5K Views · 12 · 29 · 163 · 25 · Read 12 replies · Sign up now to get your own personalized ...