Hash recovery: the limits of the browser
Last updated: September 28, 2026
Kortex Hash does real computation, including on your graphics card. But let us be honest about what a browser can and cannot do.
Why the GPU speeds things up so much
Recovering an input by comparison means repeating the same operation (hash, compare) on billions of independent candidates. That is exactly what a graphics card is made for: thousands of small cores working in parallel. Where a processor tests a few million MD5 hashes per second, a GPU tests hundreds of millions, even billions. Our brute forceengine uses WebGPU for MD5, SHA-1 and SHA-256 when possible.
The mathematical wall
Acceleration does not change the fundamentals: each added character multipliesthe number of combinations by the size of the character set. An 8-character password from 95 possible characters is 95⁸ ≈ 6.6 × 10¹⁵ combinations. Even at a billion per second, that takes more than two months; at 12 characters, we are talking millions of years. That is why the toolestimates the time before starting and refuses the impossible.
Browser vs. native tool (hashcat, John the Ripper)
A native tool like hashcat accesses the graphics card driver directly, uses very low-level optimizations and runs without a browser’s constraints. On the same hardware, it is much faster than WebGPU. A browser remains ideal for understanding, testing your own hashes and handling simple cases, but for a serious audit of fast hashes, professionals use dedicated offline tools, often on several GPUs.
What about precomputed hash databases?
Some online services query huge precomputed tables (terabytes). That is not realistic in a browser, and it is not our approach: nothing is uploaded, everything is computed on your machine. Against these tables, the countermeasure is simple and well known: aunique salt per password makes them useless.
Key takeaways
- The GPU speeds things up enormously, but does not beat mathematics.
- A long, varied password remains out of reach, here as anywhere else.
- For intensive professional use: native offline tools, with authorization.
- The best defense remains a long, unique password, properly hashed and salted.