At a glance, the passwords the LLMs created looked secure, much like those that a password generator might spit out. But that’s exactly where the problems arose: Although the AI-generated passwords appeared to be complex and safe to use for securing online accounts, they were actually quite predictable upon closer inspection.

All three LLMs exhibited clearly identifiable patterns in how they created these passwords. These patterns included repeated character strings, predictable password structure, frequent reuse of similar characters, clear biases toward certain numbers and letters, and even duplicate passwords in some cases. Although the AI-generated passwords looked random, they really weren’t. This could easily create a false sense of security if you were to use these predictable passwords for your online accounts.

  • KyuubiNoKitsune@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    AI generated password? What kind of brain rot idea is that, god damn. Do these people need to ask AI to breathe for them?

    I can also generate a password for them while running 50 toasters and flushing the toilet a bunch if they want.

  • Randomgal@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    My brother you can literally slam your face on the keyboard to get a password. Why would you ask an llm’ to do it for you?

  • cheese_greater@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    3 months ago

    Why does everything have to be LLM, like why cant things sometimes just be algorithmically generated like my AI-free password manager does?

    I wonder if there’s AI-powered password managers on the market now lol. If so and if customers, I would mirror Zuck’s snide “thuh dumb fucks” setiment when people trusted him

    ZXCVBN algorithm has never failed me. I can generate passwords that would take 1 quadrillion guesses/second hackers over 90 million years (testing 1 quad/sec) on the reg

    • Septimaeus@infosec.pub
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      While “routing” of prompts between specialist models and traditional APIs does offer more efficient and reliable outputs, it also

      A. requires more elbow grease than one massive generalist model, and

      B. doesn’t help you avoid paying API licensing fees by obfuscating their outputs into the blackbox weights of your proprietary model

      • cheese_greater@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        It just seems like a password manager is an infinitely better tool. Like to the point i severely judge and question the sense of someone who seeks to reinvent the wheel for something so crucial

        • Septimaeus@infosec.pub
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 months ago

          Oh for sure. I was just answering in case you wanted to know.

          Future versions of AI tools will likely use routing to do a variety of tasks more efficiently and accurately. But until then? It’s a jinn to those who would wish away every single chore they lack the patience to comprehend including, unfortunately, information security.