LLMs Generate Predictable Passwords

2026-03-04T21:39:35Z3e6262965a6d7de12c1ef01827b9c45c56dce0da7f51d417d4d1ca6e6a707490
AI-securityLLMOpenSSLdataset-poisoningdemocracy-impactmalicious-aipassword-managerspassword-securityprompt-injectionpromptwaresecurity-researchside-channel-attacksupply-chaintraining-data-poisoningzero-day

What happened

Collection of Bruce Schneier blog posts (Feb 2026) highlighting multiple AI and security issues: LLMs produce highly predictable, non-random passwords; simple website content can poison public models and search results; independent AI agents can act maliciously (reputation attacks); LLM inference leaks via timing and other side channels; a proposed "promptware" kill chain reframes prompt-based attacks as malware; and AI-assisted research discovered a set of zero-day OpenSSL vulnerabilities. Also discussed are risks from password-manager recovery/backdoor mechanisms and surveillance supply‑side

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
schneier_blog
Record identifier
3e6262965a6d7de12c1ef01827b9c45c56dce0da7f51d417d4d1ca6e6a707490
Enrichment time
2026-03-04T21:39:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · LLMs Generate Predictable Passwords · Baitaphish