Skip to main content
Calcimator

Attack Probability Calculator

Comprehensive cryptographic attack analysis. Brute force, birthday attacks, side-channel risks, password strength, and key derivation security.

About this calculator

This tool models five distinct cryptographic attack scenarios behind one mode selector, and each mode reads only its own subset of inputs — switching modes changes which fields drive the results entirely. Brute Force Analysis estimates how long an attacker at a given combined hash rate would need to search a key space of a given bit size for a target success probability, then classifies the result into a plain-language feasibility rating from Trivial through Thermodynamically Impossible. Birthday/Collision Attack applies the birthday paradox to hash functions, showing how much smaller the number of attempts needed for a collision is compared to a brute-force search of the full hash space — the square-root relationship that makes hash output size matter more than intuition suggests.

Side-Channel Risk assesses timing, power analysis, cache, and electromagnetic radiation threats based on implementation type and how much physical or measurement access an attacker has, correctly treating an attack vector as not applicable — rather than an unknown, moderate risk — when the required access level isn't present, such as scoring power analysis as zero risk when there's no physical access to measure. Password Attack compares a password's effective entropy against realistic cracking speeds for both fast general-purpose hashes and deliberately slow password-hashing functions, while Key Derivation Security checks whether a chosen KDF's parameters meet current OWASP guidance for resisting GPU and ASIC-accelerated attacks.

Progress0%

Step 1 of 2

How to Use This Calculator
  1. Choose an Attack Type: Brute Force Analysis, Birthday/Collision Attack, Side-Channel Risk, Password Attack, or Key Derivation Security.
  2. For Brute Force Analysis, enter the key space in bits, attacker hash rate, parallel devices, and target success probability.
  3. For Birthday/Collision Attack, enter the hash output size in bits, desired collision probability, and items generated.
  4. For Side-Channel Risk, select the implementation type, attacker access level, and measurement precision to see timing, power, cache, and EM radiation risk.
  5. For Password Attack, enter password length, character set size, known patterns, and bcrypt hashing cost.
  6. For Key Derivation Security, select the KDF algorithm and enter iterations/cost, memory, and parallelism to check OWASP compliance.
  7. Review the calculated outputs -- such as time to crack, feasibility, collision probability, overall risk, strength rating, or OWASP compliance -- depending on the selected mode.

What each input means

Attack Type
Calculation mode to use.
Key Space (bits)
AES-128 = 128 bits
Attack Rate (hashes/sec)
1e12 = 1 trillion/sec
Hash Output (bits)
MD5=128, SHA-256=256
Items Generated
How many hashes created
Password Length
Desired password length.
Character Set Size
95 = printable ASCII
Hashing Cost (bcrypt)
bcrypt cost factor (10-14)
Iterations/Cost
PBKDF2: 100000+, bcrypt: 12, Argon2: 3
Memory (MB)
For scrypt/Argon2
Parallelism
For Argon2

How this is calculated

Formula

Time = KeySpace / AttackRate | Birthday = √(π/2 × N)

Worked example, using the default values

  1. Identify Input Parameters
    4 parameters
    Attack Type = 0, Key Space (bits) = 128, Attack Rate (hashes/sec) = 1000000000000, Parallel Devices = 1 = 19 input(s) provided
  2. Calculate Time to Crack
    Time to Crack
    5391448762278159000 = 5391448762278159000
  3. Calculate Feasibility
    Feasibility
    Beyond current technology = Beyond current technology
  4. Calculate Total Key Space
    Total Key Space
    3.402823669209385e+38 = 3.402823669209385e+38
  5. Calculate Energy Cost
    Energy Cost
    4.726143985013035e+21 = $4,726,143,985,013,035,000,000

Engine last updated . Checked against 6 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

Why does switching Attack Type change which inputs and outputs actually matter?

Each of the five modes models a genuinely different kind of attack with its own relevant variables — key space size matters for brute force, hash output size matters for collision attacks, physical access level matters for side channels — so the calculator only reads the inputs specific to whichever mode is currently selected. Inputs left over from a different mode simply aren't referenced by the active calculation.

In Side-Channel Risk mode, why does 'no physical access' score differently from an unrecognized risk level?

Power analysis genuinely requires physical access to measure a device's electrical draw, so when an attacker only has remote access, that attack vector is correctly scored as zero risk rather than an ambiguous default. Treating 'not applicable' the same as 'unknown' would have incorrectly inflated the overall risk score for remote-only threat scenarios where a whole category of physical attacks simply doesn't apply.

Why does the same password show a dramatically different crack time against MD5 versus bcrypt?

MD5 and SHA-256 are fast general-purpose hash functions designed to verify data quickly, which makes them poorly suited for password storage since an attacker can compute billions of guesses per second. bcrypt and Argon2 are deliberately slow, tunable password-hashing functions built specifically to make each guess expensive, which is why the same password entropy translates into a dramatically longer crack time under bcrypt than under a fast general-purpose hash.

What does OWASP Compliant actually check in Key Derivation Security mode?

It compares your chosen KDF algorithm's parameters against minimum thresholds commonly cited in current OWASP password storage guidance — iterations alone for PBKDF2 and bcrypt, memory alone for scrypt, and memory and iterations together only for Argon2id. Falling short of the relevant threshold means the configuration is weaker than currently recommended best practice, even if the algorithm choice itself is otherwise sound.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.