
AI systems generate weak passwords, jeopardizing cybersecurity
AI systems generate weak passwords, jeopardizing cybersecurity
- Irregular's research revealed that AI models ChatGPT, Claude, and Gemini generated predictable passwords.
- Predictable password patterns significantly weaken cybersecurity, making them vulnerable to hacking.
- Experts advise against using AI-generated passwords and suggest adopting passkeys for better security.
Story
In a recent study by AI cybersecurity firm Irregular, research highlighted serious concerns regarding the use of artificial intelligence in generating passwords. The study, which has been verified by Sky News, indicated that leading AI models—including OpenAI's ChatGPT, Claude from Anthropic, and Google's Gemini—produced passwords that were far from secure. These passwords exhibited clear and predictable patterns that could easily be exploited by cybercriminals using automated tools. This revelation raises alarm bells for both users relying on AI-generated passwords and developers integrating AI into their coding efforts. The findings underscore a significant issue in modern cybersecurity practices, where many individuals and organizations might unknowingly compromise their security by relying on passwords created by AI. Irregular's co-founder Dan Lahav emphasized the dangers of using AI for password generation, noting that such passwords lack true randomness and instead reflect patterns found within their training data. This creates a dangerous illusion of strength that does not hold up against real-world hacking attempts. According to the firm, some generated passwords required mathematical analysis to expose their weaknesses, while others were evidently weak and could be spotted with the naked eye. As part of their research, Irregular tested a sample of password outputs from the AI models, revealing that a significant number of them were not unique, raising further questions about their effectiveness for securing accounts. For instance, a sample password generated by Claude AI yielded only 23 distinct passwords out of a sample size of 50. While one password checker suggested that a Claude-produced password could take 129 million trillion years to crack, experts warn that even older computers could break these passwords in much shorter timeframes. The concerns extend beyond individual users as the study points out that developers, increasingly using AI for code generation, also face risks without realizing it. There is a growing call from experts for AI models to employ methods for generating truly random passwords similar to how humans might utilize a calculator for complex computations. In light of these findings, experts also recommend moving towards more secure alternatives such as passkeys, which offer an easier and more secure means of user authentication than traditional password systems.
Context
economic global insight market policy impact economic trends impact market geopolitical policy shift data geopolitical impact global economic trends insight impact data geopolitical impact global insight geopolitical global analysis shift geopolitical impact geopolitical market insight trends insight geopolitical shift data geopolitical insight trends policy impact trends strategic policy market shift impact geopolitical geopolitical geopolitical shift analysis global policy market market policy data impact market global economic geopolitical insight insight analysis data data insight market trends economic economic global market geopolitical...