LLM-generated passwords (generated directly by the LLM, rather than by an agent using a tool) appear strong, but are fundamentally insecure, because LLMs are designed to predict tokens – the opposite of securely and uniformly sampling random characters.

    • Kogasa@programming.dev
      link
      fedilink
      arrow-up
      37
      arrow-down
      1
      ·
      5 months ago

      People are using LLMs to diagnose disease, write prescriptions, deny health care claims, deny loans and grants, write scientific papers, review scientific papers, draft engineering and architectural documents, and talk to their loved ones

      Despair

    • Steve@communick.news
      link
      fedilink
      English
      arrow-up
      6
      ·
      5 months ago

      Very well. If you don’t want me to tell you the truth about people using LLMs to make passwords, I won’t.

    • Ephera@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      5 months ago

      I imagine, it’s a matter of asking it to generate some configuration and one of the fields in that configuration is for a password, so the LLM just auto-completes what a password is most likely to look like.

  • Phoenixz@lemmy.ca
    link
    fedilink
    arrow-up
    11
    ·
    5 months ago

    LLM-generated passwords

    This is akin to asking Karen from accounting to generate a password for you, and trusting that it will be a true random and secure password and that she won’t yap about it to everyone.

    That statement is one of the painfully dumbest things I’ve read in my life, and I’ve read the bible.

  • mr_anny@sopuli.xyz
    link
    fedilink
    arrow-up
    3
    ·
    5 months ago

    Not again this horrible web design/engine whatever laggin/stuttering the way it almost induce a epileptic seizure in me.