Estimate how long it would realistically take an attacker to crack a password after a breach, based on hashing method, password complexity, and attacker capability. This is an educational offline-attack model.