Password Hashing & Key Stretching: Salt, Iterations and Brute-Force Cost
Interactive 3D key-stretching simulator: tune password entropy, KDF iteration count, attacker hardware and salting, and watch a hash chain visualize how each defense multiplies the time needed to brute-force a password or an entire leaked database.
Storing a password safely is not just about picking a strong hash function — it's about making every single guess expensive. This simulator models a key-derivation function like PBKDF2, bcrypt or Argon2: a hash chain repeated N times per guess, visualized as a spiraling tower of glowing links that lengthens as the iteration count grows. Tune the password's entropy, the KDF's iteration count and the attacker's hardware to see the estimated time to brute-force a single account, then flip the salt toggle to see why an unsalted database lets one precomputed rainbow table crack every leaked hash almost for free, while a salted one forces the attacker to redo the entire iterated search account by account.
This simulation allows you to explore the core principles of cryptographic algorithms like AES and RSA. By manipulating encryption keys and observing the resulting ciphertext, you can gain a deeper understanding of how data is secured and protected.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install