Why LLM-Generated Passwords Are Dangerously Insecure

irregular.com

19 points by zdw 4 days ago


catlifeonmars - a day ago

This article has “why stabbing yourself with a screwdriver is bad” vibes.

ks2048 - a day ago

Had me wonder - if you ask an LLM for a random number 1...100, what distribution do you get? Surely many have run this experiment. Here's a link that looks like a good example, https://sanand0.github.io/llmrandom/

gmuslera - a day ago

This asks for a dictionary attack, not of common words, but for tokens from training that have some weight related to good passwords.

At least regarding “normal” text generation, if you tell somewhat to the LLM that generate a Python script to write down a random password and use it it may have better quality.

petcat - a day ago

> LLM-generated passwords (generated directly by the LLM, rather than by an agent using a tool)

This seems like kind of a pointless analysis to me? Humans also generate bad passwords. It's why we use crypto-hardened RNG tools.

himata4113 - a day ago

huh, for me it just generates <username>123 when I ask it to generate a password lol, sometimes adds a !, more often it just forces changeme rather than having any password.

Mordisquitos - a day ago

I only clicked on the article with no intention of reading it (no time), but rather out of morbid curiosity as to why on earth anybody would need to be told that LLMs should absolutely not be used to generate passwords.

> [...] Despite this, LLM-generated passwords appear in the real world – used by real users, and invisibly chosen by coding agents as part of code development tasks, instead of relying on traditional secure password generation methods.

Jesus F'ing Christ. I hope to have time to read the whole thing later.

CrzyLngPwd - a day ago

The article reads like it was written by a machine.

Havoc - a day ago

why would you LLM generate a password?!?

camgunz - a day ago

Honest question, how much money would I make off an MCP service to generate passwords for claws and agents. Is there still gas left in the griftmobile, are prospectors still in need of shovels, will the gods bless my humble, shameless lunge for my slice of the pie?

weare138 - a day ago

If anyone is that desperate for a secure random password here's a Perl one-liner I came up with that will generate random cryptographically secure passwords with all unique characters using /dev/urandom. No dependencies:

  perl -E 'while (open($_,"/dev/urandom") && $#p+1 != $ARGV[0]) { $_ = getc $_, push @p, grep !$u{$_}++, /[!-~]/g } say @p' 24

Minified:

  perl -E 'while(open($_,"/dev/urandom")&&$#p+1!=$ARGV[0]){$_=getc$_;push@p,/[!-~]/g}say@p' 42
stanmancan - a day ago

Obligatory https://xkcd.com/221/

dfir-lab - a day ago

[dead]

Terr_ - 4 days ago

[dead]