Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
発見する
投稿する
  • ようこそAIIDへ
  • インシデントを発見
  • 空間ビュー
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • インシデントレポートを投稿
  • 投稿ランキング
  • ブログ
  • AIニュースダイジェスト
  • リスクチェックリスト
  • おまかせ表示
  • サインアップ
閉じる
発見する
投稿する
  • ようこそAIIDへ
  • インシデントを発見
  • 空間ビュー
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • インシデントレポートを投稿
  • 投稿ランキング
  • ブログ
  • AIニュースダイジェスト
  • リスクチェックリスト
  • おまかせ表示
  • サインアップ
閉じる

レポート 2962

AI Can Now Crack Most Passwords in Less Than a Minute
extremetech.com · 2023

We've been warned for years to use strong passwords online, but not everyone heeds those warnings. Thanks to the increasing power of AI, even those who exercise reasonable caution may find their passwords insufficient. Cybersecurity firm Home Security Heroes fed millions of actual passwords into an artificial intelligence to see how long it would take to crack them. The answer is "not as long as you'd expect." The system was able to crack most passwords in less than a minute.

Home Security Heroes ran this test with the PassGAN password generator. Unlike most password generators, PassGAN uses a Generative Adversarial Network (GAN) to learn from real passwords to create new ones. A GAN in this context consists of two opposing neural networks, a generator and a discriminator. The generator network created fake data, and the discriminator is tasked with picking out real data in a sea of fakes. Over time, the generator and discriminator become better at what they do, making the overall model more effective.

PassGAN was provided with 15,680,000 common passwords from the RockYou data set in this test. For the unaware, RockYou was a social widget hacked years ago, revealing millions of unencrypted passwords. It has since been a commonly utilized data set in security research. The test excluded passwords longer than 18 characters and shorter than four. Home Security Heroes says the AI cracked 51% of those passwords in less than one minute. Some people always heed warnings to use secure passwords, and their data was harder to crack. PassGAN decoded 65% of passwords in an hour or less, hitting 71% in about a day. It took another month to boost that to 81%.

So, the good news is the most robust passwords are still functionally impossible to crack, but a password you might think is strong could be a breeze for today's AI. The firm reports a 10-character password with numbers and lower-case letters would be cracked in the sub-1-hour group with 65% of all tested passwords. However, adding another layer of complexity with upper case letters or special characters boosts the cracking time to an estimated five years.

If you want to ensure your passwords are in the currently uncrackable group, Home Security Heroes recommends ensuring it's at least 15 characters long. You should use a combination of letters (upper and lower case), numbers, and special characters. The firm also recommends changing passwords frequently. If you swap important passwords every few months, there won't be time for an AI to crack it before you're on to something else. The cat-and-mouse game will never end, though. Eventually, AI may even be able to figure out these more complex passwords, which is why some major tech heavyweights are working to do away with passwords entirely.

情報源を読む

リサーチ

  • “AIインシデント”の定義
  • “AIインシデントレスポンス”の定義
  • データベースのロードマップ
  • 関連研究
  • 全データベースのダウンロード

プロジェクトとコミュニティ

  • AIIDについて
  • コンタクトとフォロー
  • アプリと要約
  • エディタのためのガイド

インシデント

  • 全インシデントの一覧
  • フラグの立ったインシデント
  • 登録待ち一覧
  • クラスごとの表示
  • 分類法

2024 - AI Incident Database

  • 利用規約
  • プライバシーポリシー
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 300d90c