LLM-generated passwords (generated directly by the LLM, rather than by an agent using a tool) appear strong, but are fundamentally insecure, because LLMs are designed to predict tokens – the opposite of securely and uniformly sampling random characters.

you are viewing a single comment's thread
view the rest of the comments
[–] 13 points 5 months ago

LLM-generated passwords

This is akin to asking Karen from accounting to generate a password for you, and trusting that it will be a true random and secure password and that she won't yap about it to everyone.

That statement is one of the painfully dumbest things I've read in my life, and I've read the bible.

  • source