N = 10,000 iterations Salted — per-account rebuild required
Hash chain link (lit = active iterations) Attacker probe (illustrative pace)
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Password Hashing & Key Stretching: Salt, Iterations and Brute-Force Cost

Storing a password safely is not just about picking a strong hash function — it's about making every single guess expensive. This simulator models a key-derivation function like PBKDF2, bcrypt or Argon2: a hash chain repeated N times per guess, visualized as a spiraling tower of glowing links that lengthens as the iteration count grows. Tune the password's entropy, the KDF's iteration count and the attacker's hardware to see the estimated time to brute-force a single account, then flip the salt toggle to see why an unsalted database lets one precomputed rainbow table crack every leaked hash almost for free, while a salted one forces the attacker to redo the entire iterated search account by account.