Try it corner

Poke things. Break nothing. Every tool runs entirely in your browser: nothing you type is sent anywhere, saved or logged.

Hash & encode playground

See encoding and hashing side by side. Hashing uses your browser's built-in Web Crypto API.

Base64 · encoding
—

Reversible by anyone. It changes the format, not the secrecy.

SHA-256 · hashing
—

A one-way fingerprint, always 64 hex characters. Change one letter and the whole thing changes.

Decode Base64

Decoded
—

Encryption needs a secret key, which is exactly why it isn't here. Hashing vs encryption vs encoding →

Password strength & crack time

100% private: this runs only in your browser. Nothing is sent, saved or logged. Still, don't type your real password: try one that looks like it.

Start typing to see how strong it is.

Estimated time to crack
AttackSpeed assumedTime
Online login with rate limiting10 guesses / sec—
Stolen hashes, slow algorithm (bcrypt, Argon2)10,000 / sec—
Stolen hashes, fast algorithm (MD5, SHA-1) on one GPU100 billion / sec—
  • At least 12 characters
  • Lowercase letters
  • Uppercase letters
  • Numbers
  • Symbols like ! ? # %
  • Not a common password or pattern
How this estimate works (assumptions)
  • Strength is estimated from length and which character types you used (lowercase, uppercase, numbers, symbols).
  • Common passwords, keyboard patterns like "qwerty", repeated characters and "Password1!"-style variations are treated as guessed almost instantly, because attackers try those first.
  • Times assume the attacker finds it halfway through, on average, at the speeds shown in the table.
  • Real attackers use smarter rules, so treat a long time as "probably fine", not a guarantee.
  • MFA stops most account takeovers even when a password is cracked.

Tip: four random words beat one “clever” word. purple-rocket-tea-lamp

IAM policy explainer

Paste an AWS IAM policy (JSON). You'll get each statement in plain English, plus warnings for risky patterns like "Action": "*" or "Principal": "*". Parsed locally; nothing is uploaded.

A teaching aid, not a full security review. For real accounts, AWS IAM Access Analyzer checks policies against your actual setup.

Spot the phishing link

8 links. For each one, decide: safe or phishing? They're shown as text only, so nothing is clickable.

    Rule of thumb: find the first single “/” after https://, then read the domain right to left.

    Binary converter

    Type a number from 0 to 255, or flip the switches.

    Binary 0010 1010

    Math 32 + 8 + 2 = 42

    Each switch is worth double the one to its right. That's binary. Watch the explainer →