Skip to main content

AI can probably crack your password in seconds

We can now add easily cracking passwords in a matter of seconds to the list of things that AI can do.

Cybersecurity firm Home Security Heroes recently published a study uncovering how AI tools analyze passwords and then use that data to crack the most common passwords used on the web.

Recommended Videos

Using the PassGAN tool, the firm was able to figure out common four- to seven-character passwords in seconds. It also didn’t matter if there was variation in uppercase and lowercase letters or if numbers were included. The shorter and more simple passwords were easier for the tool to crack.

Please enable Javascript to view this content

PassGAN uses the latest Generative Adversarial Network (GAN) machine learning model that has been fed over 15 million common passwords. These passwords have been derived from the RockYou data set, which has collected information from popular breaches of companies such as MySpace and Facebook. The RockYou data set has become a commonplace source for machine learning password-cracking models, according to Tom’s Hardware.

PassGAN was able to crack passwords with up to six characters instantly until symbols were included — for those, it took at least four seconds. The tool was able to crack passwords with up to seven characters instantly until they included uppercase and lowercase letters; then it took at least 22 seconds.

Overall, the study determined that passwords longer than 12 characters with a combination of uppercase and lowercase letters, numbers, and symbols were the most challenging to crack. For example, a 15-character password with such a mix would take 14 billion years for AI to crack, according to PassGAN.

However, in common practice, most users are still very much at risk for a password breach. Home Security Heroes notes that for most of the common passwords, at least 51% of those tested were cracked in less than a minute. Many that are more challenging can still be figured out with time; 65% of common passwords can be cracked in less than an hour, 71% in less than a day, and 81% in less than a month.

Tom’s Hardware noted via Statista that six out of 10 Americans have a password between eight to 11 characters. While an 11-character password with uppercase and lowercase letters, numbers, and symbols can put you in the safe zone of 356 years to crack, many users might still be at risk with shorter, less unique passwords.

Users should keep in mind common password safety practices such as not keeping the same passwords for multiple accounts, changing passwords regularly, and using trusted password managers.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
How you can try OpenAI’s new o1-preview model for yourself
The openAI o1 logo

Despite months of rumored development, OpenAI's release of its Project Strawberry last week came as something of a surprise, with many analysts believing the model wouldn't be ready for weeks at least, if not later in the fall.

The new o1-preview model, and its o1-mini counterpart, are already available for use and evaluation, here's how to get access for yourself.

Read more
The viral ‘GPU purse’ costs $1,024 — but you can make your own for $40
A purse made out of a GT 730 GPU.

I never thought the best graphics cards would become a fashion statement, much less some of the worst, but here we are. Over the weekend, a website called GPU Purse went live with a listing for a discarded Nvidia GT 730 GPU -- a $20 used GPU -- that had been turned into a handbag. You'll just need to shell out $1,024 for the bag, which, according to the product page, fits a phone and comes complete with a long or short chain.

One look at the website sets off alarm bells, especially for a product that's over $1,000, but it appears there's some legitimacy behind it. Financial Times reports that the GPU Purse is the brainchild of Tessa Barton, a New York Times alum and current pretraining engineer at Databricks. Barton reportedly set up a Shopify store in haste after a post on X (formerly Twitter) went viral last week with over 1.4 million impressions.

Read more
The Apple Vision Pro can now be controlled only by your mind
Mark has ALS but can use the Vision Pro via Synchron's Stentrode.

The Apple Vision Pro is already incredibly easy to use, largely thanks to its lack of controllers. You just look at a control and tap your index finger to your thumb to select.

But hand gestures aren’t always easy or possible for the millions of people worldwide who have paralysis of the upper limbs. Synchron recently announced a spatial computing breakthrough that lets users of the Stentrode BCI (brain computer interface) implant control an Apple Vision Pro.

Read more