Unlocking the Dangers: How AI Threatens Your Password Security

How AI Threatens Your Password Security

While AI technology offers numerous benefits, its potential misuse in password security cannot be ignored.

You may have heard of artificial intelligence (AI) technology’s many cool capabilities, such as assisting doctors or predicting the weather. However, there is something not-so-cool we need to discuss: AI could make our passwords less safe, which is concerning.

In today’s digital world, safeguarding our personal and sensitive data from unauthorized access is crucial. To prevent potential cyber attacks, we are often advised to create intricate passwords using unique combinations of characters and update them frequently. However, while AI has enabled us to achieve remarkable technological feats, it has also given cyber attackers powerful tools to bypass security measures.

Recent research by Password Manager shows that scammers are using AI-powered tools, like ChatGPT, Google’s Bard and Microsoft’s Security Copilot, to conduct phishing attacks, resulting in increased success rates in acquiring sensitive data and login credentials. The study also found that 52 percent of respondents believe AI has made such threats more prevalent. This revelation underscores the urgency for the digital security industry to confront the swiftly evolving risks tied to AI and take proactive strides toward their mitigation.

This article explores additional instances where AI technology compromises password security, highlighting the complex challenges of AI and cybersecurity.

AI can decode keystrokes

Have you ever considered that the sounds of your keyboard might give away what you’re typing? Computer scientists from the Universities of London, Durham and Surrey have created an AI system that can collect sensitive data by eavesdropping on keyboard sounds. The accuracy rate of the AI model in deciphering keystrokes was 93 percent when recorded through Zoom on a Macbook but rose to 95 percent when recorded with an iPhone 13 mini.

According to the researchers, keyboards are increasingly vulnerable to attacks that exploit acoustics. Hackers use side-channel attacks to obtain information such as keystroke sounds or a computer’s power consumption rather than directly targeting the system’s code. Side-channel attacks exploit weaknesses in a computer system’s physical properties to gain unauthorized access and steal sensitive data.

You can defend against this attack by utilizing touch typing, which can befuddle the model and reduce its accuracy to 40 percent. Touch typing involves typing without looking at the keyboard and relying on muscle memory to find keys. A change in typing style, using touchscreen keyboards and playing sounds on a speaker are other countermeasures. Modifying the acoustics of your keyboard can also make the AI unusable. 

Password-cracking tool

According to a recent study by Home Security Heroes, a cybersecurity company, passwords have become increasingly vulnerable to attacks from AI-powered tools. The study demonstrated how quickly passwords can be cracked using PassGAN, an AI-powered tool that uses Generative Adversarial Networks (GANs) to learn patterns and distribution of real passwords from past data breaches. PassGAN generates multiple combinations to crack a user’s password.

The study found that passwords with more than 18 characters are the most secure against AI-powered hacking tools. Even a password containing only numbers would take an AI tool around ten months to crack. However, an 18-character password that includes a combination of numbers, lowercase and uppercase letters and symbols would take an unimaginable six quintillion years for an AI tool to crack, equivalent to six billion years.

To safeguard against AI-powered password attacks, consider using long, complex and unique passwords, employ password managers, enable multi-factor authentication, update passwords regularly and stay informed about cybersecurity trends.

AI-driven thermal attack

Computer security researchers have recently made a breakthrough that might make you think twice before typing out your next login. Researchers at the School of Computing Science at the University of Glasgow have developed an AI-driven system called ThermoSecure that can guess passwords in mere seconds by analyzing the heat signatures left behind by fingertips on keyboards and screens. The researchers developed this system to demonstrate how thermal imaging cameras and machine learning create thermal attacks.

Users must be cautious about leaving their devices unattended after typing passwords on a computer keyboard, smart device screen or ATM keypad. A thermal camera can capture heat patterns of where fingers touch, revealing the password or ATM pin. Analyzing the relative intensity of warmer areas can determine letters, numbers and symbols used and their order. ThermoSecure AI can reveal 86 percent of passwords through thermal image analysis within 20 seconds, 76 percent within 30 seconds and 62 percent within 60 seconds.

To protect against a thermal attack, you must be aware of your surroundings when entering sensitive information in public. It is important to ensure that nobody is watching and, if possible, consider resting your palms on the device to obscure heat patterns or wear gloves or finger protection. It is highly recommended to use multi-factor authentication whenever possible and safeguard all authentication factors to the best of your ability to prevent potential security breaches.

Staying ahead

The potential dangers posed by AI to password security cannot be ignored. Traditional password protection measures are no longer enough to protect our sensitive information. Adopting proactive strategies to defend against AI-driven threats is crucial as AI evolves. One must remain vigilant and ensure digital safety, including frequent software updates, robust threat intelligence capabilities and continuous monitoring. By doing so, you can stay ahead of the curve and protect our sensitive information from falling into the wrong hands.

Also read:

Header image courtesy of Pexels

SHARE THIS STORY

Share on facebook
Share on twitter
Share on linkedin
Share on email

RELATED POSTS

Who Builds the Conscience of the Machine?

Regulation moves slowly. Technology does not. By the time legislators draft frameworks for artificial intelligence, the systems in question have evolved, proliferated, and embedded themselves