A key-derivation function (PBKDF2, bcrypt, scrypt, Argon2) doesn't hash the password once — it chains the hash N times, so every single guess costs the attacker N hash evaluations instead of one:
rate_eff = rate_raw / N
guesses_to_50% = 2^entropy / 2
time_crack = guesses_to_50% / rate_eff = (2^entropy · N) / (2 · rate_raw)
Doubling N (one more step on the slider is ×10) linearly multiplies the attacker's cost — exactly like adding roughly log2(N) bits of extra entropy for free, without asking the user to remember a longer password.
Salting changes a different variable: without a unique salt per account, an attacker can build one rainbow table for the whole keyspace and reuse it to crack every leaked hash almost instantly — so cracking a 10,000-account database costs about the same as cracking one password. With a unique salt, that precomputed table is worthless: the attacker must repeat the entire N-iteration search independently for every account, multiplying the database-wide cost by the number of accounts.
- Entropy slider — how unpredictable the password itself is (roughly log2 of the guess space).
- Iterations slider — the KDF's cost factor N, shown as the number of glowing links lit in the hash chain.
- Hardware — the attacker's raw (unstretched) hash throughput; GPUs and ASICs parallelize a fast hash but still pay the same N-times tax per guess.
- Salt toggle — on defeats table reuse across the whole leaked database; off lets one table crack everyone at once.
The climbing probe in the 3D view is a stylised pace indicator (log-scaled), not a literal one-guess-per-frame animation — real attack rates are far too fast to animate frame-by-frame.