MIT Technology Review Subscribe

A Pair of AIs Have Become Very Good at Guessing Your Passwords

Two neural networks can guess a quarter of the passwords in use on a website. At least that’s according to new research by a team from the Stevens Institute of Technology, who have built a so-called generative adversarial network that can make educated guesses at what your password might be.

The underlying idea is simple enough: have one neural network build something, then use another to determine its quality. It’s a concept masterminded by Ian Goodfellow, one of our 35 Innovators Under 35 for 2017, who isn’t part of this research project.

Advertisement

What the Stevens Institute team has done with that idea is have one AI chomp through tens of millions of leaked passwords to learn how to generate new ones, while the other learned how to judge whether a newly created one was compelling. Comparing their efforts to a LinkedIn credentials leak, the AI-generated passwords matched 12 percent of the real ones. When the researchers also rolled in some human-created rules from a software tool known as hashCat, they were able to guess 27 percent of passwords—as much as 24 percent more than hashCat can achieve alone.

This story is only available to subscribers.

Don’t settle for half the story.
Get paywall-free access to technology news for the here and now.

Subscribe now Already a subscriber? Sign in
You’ve read all your free stories.

MIT Technology Review provides an intelligent and independent filter for the flood of information about technology.

Subscribe now Already a subscriber? Sign in

It is, obviously, still a technique in its infancy, and it’s unclear if a 24 percent boost really warrants the weight of such advanced machine learning. But this appears to be the first time that a generative adversarial network has been used to help crack passwords, and it seems likely that the technique will improve faster than conventional approaches as it chews on more data.

At any rate, it may not be all bad news. As Thomas Ristenpart, a computer scientist from Cornell Tech in New York City, tells Science: “The new technique could also potentially be used to generate decoy passwords to help detect breaches.”

This is your last free story.
Sign in Subscribe now

Your daily newsletter about what’s up in emerging technology from MIT Technology Review.

Please, enter a valid email.
Privacy Policy
Submitting...
There was an error submitting the request.
Thanks for signing up!

Our most popular stories

Advertisement