News: 0180827892

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LLM-Generated Passwords Look Strong but Crack in Hours, Researchers Find (theregister.com)

(Thursday February 19, 2026 @05:40PM (msmash) from the security-woes dept.)


AI security firm Irregular has found that passwords generated by major large language models -- Claude, ChatGPT and Gemini -- appear complex but follow predictable patterns that make them crackable in hours, even on decades-old hardware. When researchers prompted Anthropic's Claude Opus 4.6 fifty times in separate conversations, only 30 of the returned passwords were unique, and [1]18 of the duplicates were the exact same string . The estimated entropy of LLM-generated 16-character passwords came in around 20 to 27 bits, far below the 98 to 120 bits expected of truly random passwords.



[1] https://www.theregister.com/2026/02/18/generating_passwords_with_llms/



Question is why? (Score:3)

by Valgrus Thunderaxe ( 8769977 )

Why do you need an LLM to generate passwords?

Re: (Score:2)

by sabbede ( 2678435 )

Need? You don't. "Want" because you're already too lazy to read and write for yourself? Yeah, I can see that.

Re: (Score:3)

by unrtst ( 777550 )

Exactly. It's not a question of "why would someone do that?", but one of, "What's the likelyhood of some non-insignificant number of people using it for that purpose?" And it's not just people using it, cause it's being used to orchestrate all kinds of things and will likely need to create passwords as a matter of course when doing it's tasks.

It's obvious to me why these are the results, but LLM's fool most people into believing they're thinking on some level and likely being honest. They may ask, "why woul

Re: (Score:3)

by unixisc ( 2429386 )

Password manager packages such as LastPass already offer to create random passwords. It would seem to me that LLMs should find this the easiest job to take from humans, given that they probably

- Wouldn't use something that humans would that is easy to remember, such as birthdays, social security numbers, anniversaries, etc

- Would make them as long as allowable by whichever service for which that login is being created. For instance, if a particular package allows 20 characters, it could create somethi

Re: (Score:2)

by fahrbot-bot ( 874524 )

> Why do you need an LLM ... ?

Could have stopped with that. /s

Re: (Score:1)

by BinBoy ( 164798 )

Because AI.

Re: (Score:2)

by Sloppy ( 14984 )

To get the most popular passwords, duh. These things are trained on lots of passwords, so they know which ones are the best guesses for autocompletion.

Why? (Score:2)

by Chris Mattern ( 191822 )

Even if you didn't know they were this weak, why would you want a LLM generating your passwords when a simple random number generator is guaranteed to do a better job of it?

Re: Why? (Score:4, Insightful)

by EldoranDark ( 10182303 )

Because we both know that someone somewhere is absolutely doing it already. And perhaps the responsible thing is to point out the problem and hope LLM providers might prepare a canned response for the future.

Re: (Score:2)

by sabbede ( 2678435 )

Because people are already offloading too much of their thinking to LLMs?

Which could be seen as evidence that it isn't a bubble, but I'm not making an argument about that.

Re: (Score:2)

by ukoda ( 537183 )

I think the bubble is not AI users, they will continue to grow. The bubble is in the thousands of companies who think all they need is money to become the next ChatGPT. Much like all the new crypto currencies that thought they would be the next Bitcoin.

Re: (Score:2)

by Junta ( 36770 )

I kind of agree, but think AI users will face a significant fall off when the bubble pops and a lot of folks walk away from it without critically thinking about it in the same way a lot of folks walk toward it without critically thinking about it, never having 'got it' one way or the other and just following what the apparent mass opinion is.

Also, a bubble pop would likely come with price hikes for the surviving companies under more pressure to operate at a sustainable revenue instead of loss leading, and t

Re: (Score:1)

by Anonymous Coward

Tragically common to use a LLM to solve problems that existing simple solutions already solve. It's the tech equivalent of "rolling coal" - creating waste and harm just because you can.

Because magic (Score:4, Interesting)

by abulafia ( 7826 )

Because people don't know how things work, and treat the robots like oracles.

"But ChatGPT said..." is the new "I saw it on television, it must be true."

If you're not doing something like

< /dev/urandom tr -dc _A-A-a-z-0-9 | head -c30

or some tool that does something similar, you already have problems.

Re: (Score:2)

by aaarrrgggh ( 9205 )

...and how do you store said passwords, since they need to be different for everything. A memorable password that gives access to your keychain or equivalent is no more secure. Don't get me wrong, I use OpenSSL for mine, but I fully understand that if someone has time to brute-force my random four-character computer password they have full root. Sure, they need physical access, and my logic is that by that point there are plenty of easier ways to cause me pain.

Re: (Score:2)

by abulafia ( 7826 )

Password storage is the same whether or not you use a robot-poop password.

I use Hashicorp Vault at home, because I tend to dogfood the services I run at work. But that's a bit ridiculous, I don't recommend it.

We also run a local Bitwarden installation at work, that's generally for nontechnical users and the dedicated programming staff (although I repeat myself).

For normal people, I recommend some password manager with local storage not tied to a browser, and ideally not tied to your OS. But it depend

Re:Why? (Score:4, Insightful)

by Whateverthisis ( 7004192 )

It's a byproduct of what happens with all technologies, the [1]Gartner Hype Cycle [wikipedia.org].

A new technology comes out. People immediately think it is the be-all, end-all solution to many things. People apply it to numerous things because they can .

Eventually, many of the things they claim the technology will do don't pan out. Then you head into the [2]Trough of disillusionment [wikipedia.org]. People begin to ask questions like "We can do this, but should we?" Many potential applications die off completely. The few that remain survive, and gradually grow into becoming a useful solution.

So yes, of course people used an LLM to generate passwords. Because they can. Doesn't mean they should, but we're not quite at the "should" stage of LLM applications yet.

And for the bubble talk, yes AI is a bubble. The reason it's a debate is because we talk about bubbles in binary terms, but when you look at it with the Gartner Hype Cycle, you'll see that it's not yet ready to fall, but applications like password generation and quite a few others show that it will. It won't collapse completely, because there are good applications of LLM AI; it will climb out of the trough and find valuable, useful tools. The debate about whether it's a bubble or not is irrelevant, what we should be discussing is when a contraction will happen (and it will), what it will look like when done.

[1] https://en.wikipedia.org/wiki/Gartner_hype_cycle

[2] https://en.wikipedia.org/wiki/Gartner_hype_cycle#:~:text=3.-,Trough%20of%20disillusionment,-Interest%20wanes%20as

Re: (Score:2)

by unrtst ( 777550 )

> ... a simple random number generator is guaranteed to do a better job of it?

Show me how that works. Then, would you expect a normal person to be aware of how to do that?

If it's not obvious, direct use of an RNG does not produce a usable password. The result of this isn't directly usable in most situations: dd if=/dev/random of=test_password bs=32 count=1

It wouldn't surprise me if a lot of people go to google to look for a password generator, or how to make a strong password, and wind up copy/pasting from some website. If they're already using an LLM regularly, that's probably wher

Re: (Score:2)

by Junta ( 36770 )

Because so many people assume LLM is superseding *everything*, and need explicit reminders that not only is the 'old' way so much more efficient and simple, it's even more effective than what an LLM would do.

Well, yeah, duh (Score:5, Insightful)

by TheMiddleRoad ( 1153113 )

LLMs are not random number generators. Unless somebody hand codes one in, they will just respond with statistically like responses. Statistical likelihood is 100% their modus operandi.

Re: (Score:2)

by DarkOx ( 621550 )

I wounder what happens if you run local modes and turn the temperature way way up. Of course if you make the LLM 'drunk' enough to give truly random answers you could just grab a few bytes from /dev/urandom all by your self.

Re: (Score:2)

by TheMiddleRoad ( 1153113 )

I imagine it depends on the model, and I imagine that it would still be well within the guessable range of passwords, because even then, the likelihood of a certain statistical range is high.

Re: (Score:2)

by Dan East ( 318230 )

That was my initial thought as well, until I remembered they do contain RNGs in their fundamental logic - that's referred to as the [1]temperature [ibm.com].

They found introducing an element of randomness into them made them seem more "realistic". Although clearly there are only so many alternate pathways they can take even with randomness involved.

[1] https://www.ibm.com/think/topics/llm-temperature

So, how do y'all like to craft your passwords? (Score:2)

by sabbede ( 2678435 )

Personally, I like proper sentences, but after running some old ones through an entropy checker, it looks like I need to make sure they're a little longer. "Did you eat my cat?" could be broken a little more quickly than it used to, but "Hey, did you eat my cat?" would foil even the NSA.

Yes, that is a real one I used to use. No, I don't use it anywhere anymore.

Or do I?

Re: (Score:2)

by dgatwood ( 11270 )

Was it when you lived in Springfield?

Re: (Score:2)

by sabbede ( 2678435 )

That took me a minute to figure out. But no, this was 6+ years ago.

Re: (Score:2)

by techno-vampire ( 666512 )

Years ago I knew a computer columnist and SF author, now deceased. Among other things, I did some house sitting for him. His WiFi password was quite similar to ThisIsAVeryVeryLongPassword because he figured that it was too long for the average hacker/cracker to break. Now, of course, he'd have to make it even longer.

Re: (Score:2)

by sabbede ( 2678435 )

Yeah, it's amazing how fast that could be broken now. Just a few years back, there wasn't any point in trying to crack a password longer than 12 characters. Now, it's looking more like 30, or hashing stronger than SHA512. Crazy. And Frustrating.

Re: (Score:2)

by TwistedGreen ( 80055 )

Just add some emojis and you'll be fine

Re: (Score:2)

by sabbede ( 2678435 )

Hah! Aw hell, that's probably not far off.

Though maybe not, given just how many sites out there STILL won't take spaces in passwords, despite demands for "special characters".

Re: (Score:2)

by unixisc ( 2429386 )

Yeah, a sentence or a phrase. Are spaces allowed, or should we either use "_" or capitalizations as separators? My only problem is that a lot of services/sites have a limit on how long a password can be, and some of the more retarded ones don't allow certain special characters, such as "$". It would be nice if there was a universal convention of requiring anything from 10-30 characters (say), and spelling out which special characters are, or aren't allowed

Re: (Score:2)

by sabbede ( 2678435 )

YES! I detest sites that don't allow things like spaces. Looking at you Rocket Mortgage! F-ing piss for security over there, and they just had to buy my mortgage.

The worst part is that when you see something not take a "$" or " ", it's probably because their input sanitization is sub-par. They know about SQL injection, but can't be assed to actually do something about it other than ban characters. Leaving me feeling reaaaaal secure.

I use Quickpass to rotate admin passwords (professionally, not at

Wait until it hits Powerball (Score:5, Interesting)

by thecombatwombat ( 571826 )

There was a story maybe 20 years ago where some state lottery nearly got broken because a fortune cookie company I think it was, printed a number that *almost* won. Something like 20 people won the second tier prize.

It would be utterly ridiculous if we saw 20 people win the lottery trusting ChatGPT to pick unique numbers for them.

I'd bet literally thousands of people ask that every day.

Re: (Score:2)

by ebunga ( 95613 )

There was also the rather peculiar thing that happened with the numbers from the show Lost.

Re: (Score:3)

by Ronin Developer ( 67677 )

If multiple people hit the Powerball jackpot, it is divided among the winners. They don't all get the jackpot amount so that would not bankrupt the system.

That being said, other prizes have specific cash denominations. And, others are multiplied by a PowerPlay multiplier by 1-5x (and, occasionally, 10x).

Still, it would take thousands if not millions of such winners to financially hurt the company.

And, I suspect there are rules that would trigger a fraud alert and render the drawing invalid.

Re: (Score:2)

by jabuzz ( 182671 )

In January 1995, the £16.3 million jackpot for the UK lottery was won by 133 tickets. Lots of winning tickets are already a thing.

Autocomplete failed at generating secure password (Score:3)

by fuzzyf ( 1129635 )

It's frustrating to see these headlines stating the obvious and completely disregarding how the technology actually works. Even here on Slashdot there was a user that insisted on "tHaT Is NoT hOW rEAsoNinG mODelS woRK!" as if there is some magi AI tech that is not known to the world. Transformers work in a specific way. It calculates the probably next or missing token. That is it. There is nothing else.

OF COURSE it can't generate random passwords

Password Cracking (Score:2)

by SlashbotAgent ( 6477336 )

All these studies and finding about "weak" passwords and cracking in seconds to hours.

But put these guys in the real world against a 16 character password or even vague complexity and tell them to call you when they hit it.

I guarantee that you'll never hear from them again. A vaguely complex 10 character password would take tens of years even if they got lucky and hot it in the first 25% of the keyspace.

Re: (Score:2)

by PPH ( 736903 )

You're working the wrong end of the problem. The wrong 16 character password can be cracked rather easily.

Duh (Score:3)

by RobinH ( 124750 )

LLMs are specifically designed to generate text that looks like text it has seen before. Why would you expect it to generate something unique?

Correct Horse Battery Staple? (Score:3)

by Comboman ( 895500 )

> and 18 of the duplicates were the exact same string

How much do you want to bet that string appeared as an example of a secure password in some book or website that was part of the LLM's training data?

Oblig (Score:2)

by eriks ( 31863 )

I set all my passwords to CorrectHorseBatteryStapler you insensitive Claude!

what about something tougher (Score:2)

by Provocateur ( 133110 )

LLM-generated crossword puzzles

Obligatory xkcd (Score:3)

by gwjgwj ( 727408 )

[1]https://xkcd.com/221/ [xkcd.com]

[1] https://xkcd.com/221/

Why would you use AI for anything secure? (Score:3)

by Fly Swatter ( 30498 )

Most use of AI is in a data center you don't control, that data is logged and there will be a history of your shiny new password somewhere in those logs. This is like asking your neighbor to make you a new house key.

Asking an LLM to do things it cannot (Score:2)

by gweihir ( 88907 )

Gets you something fake, and if you are unlucky, something you do not easily recognize as fake. About the worst case possible.

Deep confusion (Score:3)

by OzJimbob ( 129746 )

There appears to be deep confusion, across the public in general (and dare I say the managerial class in particular) about what large language models actually *do*. Nobody with any understanding of what these things actually are, how they would, would imagine getting one to generate a password would be a smart idea. Somehow (marketing? hype?) people have been convinced these are intelligent, do-anything machines, and I have no idea how we break that impression.

Ask it to write a password generator (Score:2)

by Yo,dog! ( 1819436 )

LLMs are inherently language based--not great for randomness. How strong are passwords produced by generators written by Opus 4.6?

Friends don't let friends use Windows 95.