Password Strength Analysis Through Social Network Data Exposure: A Combined Approach Relying on Data Reconstruction and Generative Models
By: Maurizio Atzori , Eleonora Calò , Loredana Caruccio and more
Potential Business Impact:
Finds weak passwords using online info.
Although passwords remain the primary defense against unauthorized access, users often tend to use passwords that are easy to remember. This behavior significantly increases security risks, also due to the fact that traditional password strength evaluation methods are often inadequate. In this discussion paper, we present SODA ADVANCE, a data reconstruction tool also designed to enhance evaluation processes related to the password strength. In particular, SODA ADVANCE integrates a specialized module aimed at evaluating password strength by leveraging publicly available data from multiple sources, including social media platforms. Moreover, we investigate the capabilities and risks associated with emerging Large Language Models (LLMs) in evaluating and generating passwords, respectively. Experimental assessments conducted with 100 real users demonstrate that LLMs can generate strong and personalized passwords possibly defined according to user profiles. Additionally, LLMs were shown to be effective in evaluating passwords, especially when they can take into account user profile data.
Similar Papers
Enhancing Password Security Through a High-Accuracy Scoring Framework Using Random Forests
Cryptography and Security
Makes passwords much harder for hackers to guess.
When Intelligence Fails: An Empirical Study on Why LLMs Struggle with Password Cracking
Cryptography and Security
AI can't guess passwords well from personal info.
Adversarial Machine Learning for Robust Password Strength Estimation
Cryptography and Security
Makes passwords harder for hackers to guess.