Online vs. Offline Attacks
Online attackstarget login forms directly and are limited by rate limiting, CAPTCHAs, and account lockouts — typically 10–1,000 guesses per second. Offline attacks occur when an attacker obtains a leaked password hash database. With a modern GPU cluster, they can test 100 billion hashes per secondagainst algorithms like MD5, or 10 million per second against bcrypt. This is why the same password can be “safe for centuries” online but crackable in hours offline.