LLM-generated passwords (generated directly by the LLM, rather than by an agent using a tool) appear strong, but are fundamentally insecure, because LLMs are designed to predict tokens – the opposite of securely and uniformly sampling random characters.

you are viewing a single comment's thread
view the rest of the comments
[–] 5 points 5 months ago

Getting away from more direct requests I can absolutely imagine AI offering passwords/suggestions as part of a coding session. Including "temp" passwords that look secure so "why bother changing it?".

  • source
  • parent