Quick Summary
The Securityish Brief
Experts from the AI security company Irregular conducted tests on three generative AI tools: Claude, ChatGPT, and Gemini. They prompted each tool to generate 16-character passwords containing special characters, numbers, and letters in various cases. Despite passing online password strength checkers, these passwords exhibited common patterns that could be exploited by hackers, making them less secure than they seem.
In their analysis, Irregular found that out of 50 passwords generated by Claude, only 30 were unique, with many starting and ending with the same characters. Similar patterns were observed in passwords generated by GPT-5.2 and Gemini 3 Flash, indicating a lack of true randomness. The researchers estimated the entropy of these passwords using the Shannon entropy formula, revealing that they had an entropy of around 27 bits, compared to the 98 bits expected for a truly random password.
Implications for Password Security
This finding highlights a significant risk for users and organizations relying on AI-generated passwords. The predictable nature of these passwords means they could be brute-forced in a matter of hours, even on older computers. Irregular emphasized that developers and users should not depend on large language models (LLMs) for secure password generation, as they are designed to produce plausible outputs rather than random ones.
Irregular also noted that the patterns found in AI-generated passwords could lead to increased brute-forcing attempts, especially as AI continues to be integrated into coding practices. They recommend that any passwords generated through LLMs be reviewed and rotated to enhance security.
- 1Password is a recommended third-party password manager that helps users create and store secure passwords.
- Bitwarden is another password manager that offers strong security features for managing passwords.
- The iOS and Android native password managers provide built-in solutions for mobile users to manage their passwords securely.
Key Takeaways
- Review any passwords generated by AI tools and consider changing them to enhance security.
- Use a reputable password manager like 1Password or Bitwarden to create and store strong, unique passwords.
- Enable two-factor authentication (2FA) on accounts whenever possible to add an extra layer of security.
- Regularly monitor your accounts for any unauthorized access or suspicious activity.
- Educate yourself and your team about the limitations of AI-generated passwords and the importance of true randomness.
Key Terms & Concepts
- Entropy: In this article, entropy refers to the measure of randomness in a password, with higher values indicating stronger security.
- Generative AI: Generative AI refers to artificial intelligence systems that can create content, such as text or passwords, based on learned patterns.
- Brute-force attack: A brute-force attack is a method used by hackers to guess passwords by systematically trying all possible combinations.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.