I testing the passcode strength test against dice-generated sequences, and I noticed that every time I entered a code 5 digits long, every row said less than a second, but as soon as I added one more digit, the numbers jumped up to 10 hours, 3 days, and 100 days. By the math, wouldn’t 5-digit passcode have average times to crack of one hour, 7 hours, and 10 days for each row?
I think it may be broken. There’s a table on that same phone passcode page with estimated times more in line with what you’d expect (assuming you aren’t using like 12345 or something, in which case less than a second is probably right lol).
This is why I would never take one strength calculator as gospel but rather, take the worst case from a combination of them. 6 digits should take milliseconds unhindered (doesn’t exactly take long for a computer to count to a million!) but then depend entirely on rate limiting if online or behind a secure interface (and whether anyone can find a way of bypassing it). Things like KDF would slow it down a little.
What’s KDF?
Key Derivation Function - it’s a mathematical (rather than programmatic) defence against brute force attacks. To be honest I don’t completely understand more than the gist myself.
This is presumably based on their phone passcode section, which includes rate limiting (that’s what the three different sections represent). Whether the values for the rate limiting are accurate, IDK.