The Looming Threat of AI Password Crackers – And How to Protect Yourself
Artificial intelligence is ushering in a new era of technological magic – but also of unprecedented security risks. While AI chatbots charm us with their wit and virtual assistants simplify our lives, in the shadows a more sinister breed of AI is emerging: sophisticated machine learning systems designed to crack our passwords with ruthless efficiency.
In recent years, security researchers have demonstrated the shocking power of AI to guess passwords that would take a human hacker months or years in seconds. As these tools proliferate into the hands of cybercriminals, the risk of devastating breaches skyrockets. One study found that an AI tool called PassGAN cracked over 50% of a 43 million password database in under a minute, and 81% in a day. Another showed that 20% of passwords fall to AI instantly.
The implications are sobering. With access to our email, banking, health records, and professional accounts just a password away, an AI-powered cracking attack could upend our lives. On a societal scale, the economic damage could be immense. One report projected that the cost of password-related breaches will exceed $6 trillion annually by 2024.
The good news is that by understanding the threat and putting the right defenses in place, we can protect ourselves from the coming storm of AI password crackers. In this article, we‘ll dive into the state-of-the-art in AI password hacking and reveal the steps you must take to keep your digital life secure in the age of AI.
How AI Password Hacking Works
To understand why AI password cracking is so dangerous, let‘s look at how it works. Traditionally, password cracking relied on brute force – essentially trying every possible combination of characters until the right one is found. But modern password hacking tools leverage AI to work smarter, not just harder.
One popular approach uses a machine learning method called a generative adversarial network (GAN). A GAN pits two neural networks against each other: a "generator" that tries to produce fake examples of something (like a password), and a "discriminator" that tries to distinguish the fakes from the real deal.
By training a GAN on millions of real passwords exposed in past data breaches, it learns patterns in how people craft passwords. The generator becomes adept at spitting out statistically plausible password guesses, while the discriminator learns to predict whether a password is likely to be real based on common patterns and traits.
The result is a tool that can generate and prioritize billions of high-probability guesses per second based on patterns gleaned from real password datasets. Compared to the scattershot approach of brute force, it‘s like a sniper to a shotgun.
GANs aren‘t the only AI approach to turbocharging password guessing. Other tools employ neural networks like recurrent neural networks (RNNs) that can learn patterns in sequential data, or Markov chain models that use probability to predict the next most likely character in a password.
Stacking these techniques together can yield even more formidable results. For instance, a tool called PassGAN leverages a GAN and Markov model to capture both high-level password trends and fine-grained character transition probabilities from its training data.
So how fast are these AI-powered password crackers? In one study, PassGAN:
- Guessed 20% of a 43.3 million password test set instantly
- Cracked 51% in under a minute
- Hit 71% in an hour
- Cracked 81% in a day
These numbers should send a chill down the spine of anyone relying on a password alone to secure their accounts. So what can we do?
How to Protect Your Passwords from AI
Faced with the speed and scale of AI password cracking, our old rules of thumb for "strong" passwords no longer cut it. To protect your digital life from an AI-powered attack, you need to level up your password practices in several key dimensions:
1) Go Long. Very Long.
The number one factor in fending off an AI password guesser is length. In the PassGAN study, passwords under 10 characters proved highly vulnerable regardless of their use of special characters or uncommon words. Only those above 18 characters remained largely uncracked after 30 days.
Aim for passwords of at least 15 characters, and ideally 20 or more. At that length, even an AI trying billions of guesses per second would need centuries or millennia to stumble on the right combination.
2) Crank Up the Complexity (A Bit)
While length is king, password complexity still plays a role. The more types of characters – uppercase letters, lowercase letters, numbers, symbols – the larger the space of possibilities an AI has to search.
However, remember that length trumps complexity. A long passphrase of random common words will be more secure and memorable than a short jumble of exotic symbols.
NIST‘s latest Digital Identity Guidelines emphasize this point: "Length and complexity requirements beyond those recommended here significantly increase the difficulty of memorized secrets [i.e. passwords] and increase user frustration." They suggest a minimum of 8 characters, but say longer is better.
3) Use Unique Passwords for Every Account
If you reuse the same password across accounts, a single breach can cascade into your whole digital life. With AI password crackers in play, this common practice is even more risky.
Ideally, every account should have its own unique, randomly generated password of 15 characters or more. Of course, remembering dozens or hundreds of such passwords is impossible. That‘s where password managers come in.
4) Let a Password Manager Be Your Memory
Password managers are software tools that can generate, store, and even automatically fill in complex passwords for all your accounts. All you need to remember is a single master password to unlock the manager itself.
Using a password manager is perhaps the single most impactful step you can take to harden your digital defenses against AI password crackers and other threats. Yet a 2019 Google/Harris poll found that only 24% of Americans use one. If you haven‘t made the switch, now‘s the time.
5) Secure Your Password Manager
Of course, putting all your passwords in one basket makes that basket a very attractive target. So it‘s essential to practice good security hygiene with your password manager:
- Choose a long, complex, unique master password.
- Enable two-factor authentication if available.
- Keep your software up to date.
- Only log into your manager from trusted devices.
Reputable password managers like LastPass, 1Password, and Dashlane encrypt your password vault so that even they cannot access your credentials. But you still must do your part.
6) Level Up from Password Authentication
While a strong, unique password in a well-secured manager is a big step up from "password123", it‘s still not an absolute guarantee. Given the risks posed by AI, it‘s prudent to add additional layers of protection wherever possible:
-
Enable two-factor authentication on every account that offers it. This requires a second proof of identity beyond a password, like a temporary code from an SMS or authenticator app.
-
Consider physical security keys. Hardware devices like a YubiKey only unlock when plugged in, so remote hackers can‘t access your account even with your password.
-
Demand support for passwordless standards. Standards like WebAuthn let you authenticate with biometrics or wireless FIDO security keys, removing the need to ever type a password.
Of course, these methods have trade-offs in cost and convenience compared to passwords. And for lower-stakes accounts you may still choose to stick with password authentication. The key is to assess your risk level and employ defense in depth.
The Road Ahead for AI and Authentication
Looking forward, the arms race between AI password crackers and defenders will only accelerate. Microsoft Research projects that in the next decade, a single AI model could be capable of guessing 90% of passwords in seconds on a personal computer.
At some point, we will reach a crossover where the economics make it profitable for even petty criminals to deploy AI hacking tools. Once that threshold is crossed, expect to see a spike in account takeover attacks via cracked passwords. The digital mayhem could be formidable.
Longer-term, the viability of passwords as a primary authentication method will continue to erode. Gartner predicts that by 2022, 60% of large enterprises and 90% of midsize companies will implement passwordless methods in over half of use cases – up from just 5% in 2018.
We may eventually evolve to systems based on biometrics, physical tokens, or exotic technologies like homomorphic encryption and zero-knowledge proofs that allow authentication without revealing underlying secret keys. AI too could be used proactively in continuous authentication systems that verify identity passively based on behaviors.
But in the near-to-medium term, passwords will remain a fact of digital life for most of us. Rather than resigning ourselves to being pwned by AI cyber-bandits, we must adapt our password practices to the challenges of the dawning AI age:
- Choose passwords of at least 15 characters, prioritizing length over complexity
- Never reuse passwords across accounts
- Deploy a password manager to generate and store strong unique passwords
- Enable two-factor authentication everywhere possible
- Upgrade to passwordless authentication methods when practical
Above all, take the AI password cracking threat seriously – and act now to harden your defenses. The tech giants, standards bodies, and cybersecurity community must also lean in to deploy more robust, AI-resistant authentication tools and norms.
In a world of ubiquitous AI, good password hygiene is no longer optional – it‘s a necessity. Your data, finances, and identity may depend on it. Let‘s not make it easy for smart machines to crack our keys to the digital kingdom.