Skip to content
View in the app

A better way to browse. Learn more.

ASEAN NOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

AI and our passwords ?

Featured Replies

It is known that AI has tremendeous "computing/search" capabilities. Millions of "operations" within 1 second possible. With this operational power, would it be possible to "crack" any password just by applying millions of password combinations until it says "got it" ?

Trial and error until is says "got it" ?

I posed your question to ChatGPT.

In principle, yes—but in practice, AI is not the limiting factor. The limiting factors are mathematics, computing power, and the security mechanisms protecting the password.

Here’s why:

  • If a password can be guessed offline (for example, from a stolen password hash), a computer can indeed try millions, billions, or even trillions of candidate passwords. Specialized hardware such as GPUs or ASICs is far more important than AI for this task.

  • If a password must be guessed online (logging into a website), the website usually limits attempts, delays responses, or locks the account after too many failures. In that case, even a supercomputer can’t simply blast through billions of guesses.

AI can help in some ways, but not by magically searching every possibility faster. For example, AI might:

  • Predict passwords people are likely to choose (e.g., names, dates, common patterns).

  • Prioritize guesses so likely passwords are tried first.

  • Analyze leaked password databases to identify common habits.

However, AI does not reduce the total number of possible random passwords. For example:

  • An 8-character password using only lowercase letters has about 208 billion possibilities.

  • A truly random 16-character password using upper/lowercase letters, numbers, and symbols has roughly 10³¹ possibilities—an astronomically large number. Even if a machine could test 1 trillion (10¹²) passwords every second, it would take far longer than the age of the universe on average to exhaust the search space.

Modern systems also use password hashing algorithms such as Argon2, bcrypt, scrypt, or PBKDF2, which are intentionally designed to make each password guess computationally expensive. This dramatically slows brute-force attacks.

So the key point is:

  • Weak, human-chosen passwords can often be cracked relatively quickly because they’re predictable.

  • Long, random passwords are effectively impossible to brute-force with today’s technology, regardless of whether AI is involved.

In short, AI can make password guessing smarter, but it does not make brute-force attacks against strong, random passwords practical.

Edited by Mr Awesome

16 minutes ago, swissie said:

It is known that AI has tremendeous "computing/search" capabilities. Millions of "operations" within 1 second possible. With this operational power, would it be possible to "crack" any password just by applying millions of password combinations until it says "got it" ?

Trial and error until is says "got it" ?

I don't see the political debate in this! Pardon me if I'm mistaken.

  • Author
8 minutes ago, Mr Awesome said:

I posed your question to ChatGPT.

In principle, yes—but in practice, AI is not the limiting factor. The limiting factors are mathematics, computing power, and the security mechanisms protecting the password.

Here’s why:

  • If a password can be guessed offline (for example, from a stolen password hash), a computer can indeed try millions, billions, or even trillions of candidate passwords. Specialized hardware such as GPUs or ASICs is far more important than AI for this task.

  • If a password must be guessed online (logging into a website), the website usually limits attempts, delays responses, or locks the account after too many failures. In that case, even a supercomputer can’t simply blast through billions of guesses.

AI can help in some ways, but not by magically searching every possibility faster. For example, AI might:

  • Predict passwords people are likely to choose (e.g., names, dates, common patterns).

  • Prioritize guesses so likely passwords are tried first.

  • Analyze leaked password databases to identify common habits.

However, AI does not reduce the total number of possible random passwords. For example:

  • An 8-character password using only lowercase letters has about 208 billion possibilities.

  • A truly random 16-character password using upper/lowercase letters, numbers, and symbols has roughly 10³¹ possibilities—an astronomically large number. Even if a machine could test 1 trillion (10¹²) passwords every second, it would take far longer than the age of the universe on average to exhaust the search space.

Modern systems also use password hashing algorithms such as Argon2, bcrypt, scrypt, or PBKDF2, which are intentionally designed to make each password guess computationally expensive. This dramatically slows brute-force attacks.

So the key point is:

  • Weak, human-chosen passwords can often be cracked relatively quickly because they’re predictable.

  • Long, random passwords are effectively impossible to brute-force with today’s technology, regardless of whether AI is involved.

In short, AI can make password guessing smarter, but it does not make brute-force attacks against strong, random passwords practical.

Thanks very valuable post.

21 minutes ago, swissie said:

It is known that AI has tremendeous "computing/search" capabilities. Millions of "operations" within 1 second possible. With this operational power, would it be possible to "crack" any password just by applying millions of password combinations until it says "got it" ?

Trial and error until is says "got it" ?

I don't do mobile banking for this reason. You guys might want to change your kasikorn login or whatever you use to something other than password123

21 minutes ago, swissie said:

would it be possible to "crack" any password just by applying millions of password combinations until it says "got it" ?

Trial and error until is says "got it" ?

It would have to be deliberately programmed to do so, then the company would risk severe consequences and losses. Ai does not independently decide to hack into anything. It’s a myth that Ai is human smart, it’s just a computer program is all.

Edited by novacova

1 minute ago, novacova said:

It would have to be deliberately programmed to do so, then the company would risk severe consequences and losses. Ai does not independently to decide to hack into anything.

Im sure you've seen news of openais model hack hugging face open source model already? Yes it does, anthropics model has too already and the developers are in talks with the private sector before releasing this model that could do some serious harm. Look up project glasswing for reference

Edited by harvardgrad

  • Author
3 minutes ago, riclag said:

I don't see the political debate in this! Pardon me if I'm mistaken.

Once you stand in front of a Bank, the sighn saying "Bank Holiday" (out of the blue), you will know that it will become a political debate very soon.

This time around: "Due to AI technical irregularities".

1 minute ago, harvardgrad said:

Im sure you've seen openais model hack hugging face open source model already. Yes it does, anthropics model has too already and the developers are in talks with the private sector before releasing this model that could do some serious harm. Look up project glasswing for reference

Yet it has to be programmed with such commands and the commands have validators.

  • Author
7 minutes ago, novacova said:

It would have to be deliberately programmed to do so, then the company would risk severe consequences and losses. Ai does not independently to decide to hack into anything.

Concerning this, we had a problem recently. AI programs hacking each other. The Mamas and the Papas not allowing them to do such "unallowed things". But still it happened.

2 minutes ago, novacova said:

Yet it has to be programmed with such commands and the commands have validators.

I can't really get into it much other than saying this.

Hugging Face is a non publicly traded company with a open source model that is currently not a threat to openAIs business and I doubt anyone there is interested in preventing open source models from gaining traction. Only the AI itself is intelligent enough to understand that open source models will be the preferred use of anything online in the future to prevent people's data from being stored in with these closed source companies, Google being the worst culprit.

It's not hugging face in particular but a closed source AI model like chatgpt would want to prevent people from being able to use AI privately on their own server, although its inevitable anyway.

That is as concise of a summary as I can do for you

9 minutes ago, swissie said:

Concerning this, we had a problem recently. AI programs hacking each other. The Mamas and the Papas not allowing them to do such "unallowed things". But still it happened.

Still it has to be deliberately programmed/trained by an actual human to do so. Again, ai is nothing more than a computer software. Perhaps the biggest danger is humans having personal relationships with ai believing that they’re talking to an actual form of intelligence, it’s not.

Having a memory for only important things, I use the same password everywhere, for 30 years or so. Don't trust my browsers to remember it.

Nothing much to steal, so what?

26 minutes ago, harvardgrad said:

I can't really get into it much other than saying this.

Hugging Face is a non publicly traded company with a open source model that is currently not a threat to openAIs business and I doubt anyone there is interested in preventing open source models from gaining traction. Only the AI itself is intelligent enough to understand that open source models will be the preferred use of anything online in the future to prevent people's data from being stored in with these closed source companies, Google being the worst culprit.

It's not hugging face in particular but a closed source AI model like chatgpt would want to prevent people from being able to use AI privately on their own server, although its inevitable anyway.

That is as concise of a summary as I can do for you

Ai doesn’t actually work in the idea that "the ai itself" independently understands future market preferences or has its own desire to prevent private use. Current Al models do not form independent goals, business strategies, or long-term preferences about open source versus close source systems. Any such behavior would still require human programming design and training instructions.

Create an account or sign in to comment

Recently Browsing 2

  • swissie
  • unblocktheplanet

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.