Wonderful, an AI can crack the most common passwords almost instantly

Fake hacker keyboard.
(Image credit: Getty Images - Peter Dazeley)

Just how strong are your passwords? A recent study finds that an AI password cracker can figure out the most common 4-7 character passwords in a matter of seconds. The scary part is that it includes passwords with upper and lower case letters and numbers. Not even hackers are safe from having their jobs taken by an AI!

Cyber security firm Home Security Heroes (via Tom's Hardware) fed PassGAN, an AI password cracking tool that leverages a generative adversarial network (GAN), over 15 million common passwords to train the model that could brute force some of the most common passwords in seconds.  The passwords were taken from the RockYou dataset (which included passwords for Myspace and Facebook), which was hacked back in 2009. So it's training the AI with real passwords people have used, therefore "improving the quality of predicted passwords."

Home Security Heroes found that PassGAN cracks 51% of common passwords (4-7 characters) in just under a minute, with more challenging passwords (up to 11 characters) in less than a month. A fun little tool on the site lets you type in a password, telling you how long the AI will take to crack it. Though, to be on the safe side, I wouldn't type your current password in there. 

So, I typed in the 'AbC12345' only to find out that an AI would take roughly 48 minutes to figure it out. The more extended and more random the character set, the more difficult it is for the AI to predict it. The most common password of 2023 was, according to Cybernews, you guessed it, 123456, which would take PassGAN only six minutes to crack. 

The AI struggles with passwords more than 12 or more characters long with a mixture of numbers and upper and lower case letters, and a password with 18 characters could take up to 7 billion years to crack. However, the most commonly used passwords are usually eight or fewer characters. 

Window shopping

Windows 11 Square logo

(Image credit: Microsoft)

Windows 11 review: What we think of the new OS
How to install Windows 11: Safe and secure install
What you need to know before upgrading: Things to note before downloading the latest OS
Windows 11 TPM requirements: Microsoft's strict security policy

The researchers recommend using a password with at least 15 characters with at least two upper and lower case letters, as well as tossing in a couple of symbols. Another tip is to avoid using the same password for multiple accounts and changing them every three to six months.

I actually went back and typed in 123456.!!! And it went from six minutes to 356 years, so something is to be said about tossing a couple of symbols into your new password.

The staff here at PC Gamer use password managers like LastPass, which keeps all your passwords in one safe place. However, if you want the maximum level of security, we recommend giving our password primer a look and protecting yourself.

Jorge Jimenez
Hardware writer, Human Pop-Tart

Jorge is a hardware writer from the enchanted lands of New Jersey. When he's not filling the office with the smell of Pop-Tarts, he's reviewing all sorts of gaming hardware, from laptops with the latest mobile GPUs to gaming chairs with built-in back massagers. He's been covering games and tech for over ten years and has written for Dualshockers, WCCFtech, Tom's Guide, and a bunch of other places on the world wide web. 

Read more
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Asus ROG Zephyrus G16 with an AMD Ryzen AI 9 HX 370 chip inside it.
Just in case you've forgotten all about them, AMD posts a less-than-convincing argument as to why AI PCs are better than any other type of PC
Closeup of the new Copilot key coming to Windows 11 PC keyboards
Microsoft co-authored paper suggests the regular use of gen-AI can leave users with a 'diminished skill for independent problem-solving' and at least one AI model seems to agree
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
SAN FRANCISCO, CALIFORNIA - NOVEMBER 06: OpenAI CEO Sam Altman speaks during the OpenAI DevDay event on November 06, 2023 in San Francisco, California. Altman delivered the keynote address at the first-ever Open AI DevDay conference.(Photo by Justin Sullivan/Getty Images)
In a mere decade 'everyone on Earth will be capable of accomplishing more than the most impactful person can today' says OpenAI boss Sam Altman
Retro 1990s style beige desktop PC computer and monitor screen and keyboard. 3D illustration.
Microsoft nixes details of its Windows 11 TPM 2.0 security bypass though there are still other ways of getting the latest OS on 'unsupported' hardware
Latest in AI
Closeup of the new Copilot key coming to Windows 11 PC keyboards
Microsoft co-authored paper suggests the regular use of gen-AI can leave users with a 'diminished skill for independent problem-solving' and at least one AI model seems to agree
Still image of Bastion holding a bird, taken from Microsoft's Copilot for Gaming reveal trailer
Microsoft unveils Copilot for Gaming, an AI-powered 'ultimate gaming sidekick' that will let you talk to your console so you don't have to talk to your friends
BURBANK, CALIFORNIA - AUGUST 15: Protestors attend the SAG-AFTRA Video Game Strike Picket on August 15, 2024 in Burbank, California. (Photo by Lila Seeley/Getty Images)
8 months into their strike, videogame voice actors say the industry's latest proposal is 'filled with alarming loopholes that will leave our members vulnerable to AI abuse'
live action Jimbo the Jester from Balatro holding a playing card and addressing the camera
LocalThunk forbids AI-generated art on the Balatro subreddit: 'I think it does real harm to artists of all kinds'
Aloy
'Creepy,' 'ghastly,' 'rancid': Viewers react to leaked video of Sony's AI-powered Aloy
Seattle, USA - Jul 24, 2022: The South Lake Union Google Headquarter entrance at sunset.
Google is rolling out an even more AI-heavy search engine mode because 'power users want AI responses for even more of their searches'
Latest in News
Man facing camera
The Day Before studio reportedly sues Russian website for calling infamous disaster-game a 'scam'
Will Poulter holding a CD ROM
'What are most games about? Killing': Black Mirror Season 7 includes a follow-up to 2018 interactive film Bandersnatch
Casper Van Dien in Starship Troopers
Sony, which is making a Helldivers 2 movie, is also making a new Starship Troopers movie, but it's not based on the Starship Troopers movie we already have
Assassin's Creed meets PUBG
Ubisoft is reportedly talking to Tencent about creating a new business entity to manage Assassin's Creed and other big games
Resident Evil Village - Lady Dimitrescu
'It really truly changed my life in every possible way': Lady Dimitrescu actor says her Resident Evil Village role was just as transformative for her as it was for roughly half the internet in 2021
Storm trooper hero
Another live service shooter is getting shut down, this time before it even launched on Steam