Dictionary Attack Time Calculator

Dictionary Attack Time Calculator

Unlike a pure brute-force attack that tries every possible character combination, a dictionary attack only tries entries from a fixed wordlist - often built from common passwords, previously leaked password databases, and predictable variations of both. This calculator estimates how long it takes to exhaust such a list.

Worst Case Time = Wordlist Size / Attempts Per Second
Average Case Time = Worst Case Time / 2

Example

A 14-million-entry wordlist tested at 1,000 attempts/second:

Worst Case = 14,000,000 / 1,000 = 14,000 seconds ≈ 3.89 hours (average case ≈ 1.94 hours)

Dictionary vs. Brute Force

Dictionary attacks are vastly faster than brute force against weak or common passwords, since they skip the astronomically large space of truly random combinations and focus only on realistic human-chosen passwords. But this speed advantage disappears completely against a genuinely random password that doesn't appear anywhere in any wordlist - which is exactly why long, random, non-dictionary passphrases resist this attack category so effectively, even when they're relatively short.