What happens when you need a new password?

Today, many websites force you to make one with 16 characters, uppercase and lowercase letters, numbers, and symbols.

Instead of trying to come up with something yourself, you open an AI chatbot and type: “Create a really strong password for me.”

It gives you something that looks fantastic: Long, complicated and impossible to guess. So, you copy it and make it your new password.

You just opened yourself up to new cyber-risks.

AI can do a lot of things well, but managing your passwords should not be one of them. Why is that?

When we talk about password security, we usually focus on the strength of the password itself.

  • Is it long enough?
  • Is it unique?
  • Could someone guess it?

Those things absolutely matter. The problem with asking AI to create your password isn’t necessarily that the password will be weak. After all, an AI can easily produce a string of characters that looks extremely difficult to crack.

The problem is what you do with the password afterward. Remember, you’re taking a credential that’s supposed to be secret and putting it into a conversation with a third-party service.

It’s an unnecessary risk when tools specifically designed to create and protect passwords already exist.

This sounds obvious, but consider how people actually use AI.

Maybe you ask it: “Is MyDogCharlie2018! a strong password?”

Now the AI doesn’t just know that you have a weak password, but it also knows the actual login credentials too.

Alternatively, maybe you type: “I currently use SummerVacation22!. Can you make it stronger?”

It presents the same problem.

Never paste a real password into an AI chatbot to have it evaluated, improved, stored, organized, or compared with another password. The same rule applies to PINs, recovery codes, API keys, authentication tokens, and other credentials.

If it unlocks something, keep it out of the chat!

If you use a password manager, you probably already have access to a password generator. Use that instead.

Password generators are built specifically to create strong, random credentials. Your password manager can then save the credential so you do not have to remember it, and even auto-fill into the proper fields on saved form fills. It’s a safe and secure alternative that also prevents invisible web pages from capturing more data than you mean to input.

Your web browser or operating system may also offer secure password-generation features when you create an account or change a password. That solves two problems at once: You get a strong password, and you do not have to copy it from an unrelated AI conversation into the place where you actually need it. Just be careful, because if a threat actor hacks the main browser database,

Passwords are not the only credentials that people want to discuss with AI.

Imagine asking: “What should I use as the answer to my bank’s security question about my favorite pet?”

Or: “Help me come up with memorable answers for these five account recovery questions.”

That conversation could contain information used to verify your identity. Therefore, the safest approach to security questions is to treat the answers like additional passwords, rather than simple trivia about your life.

If a website asks for your childhood street, you do not necessarily have to use your real childhood street. You can use a random answer and store it securely in your password manager. That way, someone cannot discover the answer simply by researching you online.

Just make sure you save exactly what you entered, or you’ll have trouble remembering it later!

Another tempting idea is using an ongoing AI conversation as a place to remember things.

  • “Remember that my door code is 4829.”
  • “Save my Wi-Fi login.”
  • “My backup code for this account is…”

Yet you should never use AI as a vault. Password managers are made to securely store credentials, but a general-purpose AI assistant is designed to have conversations and perform tasks. Those are very different jobs.

Use the right tool for the information you want to protect, and don’t take shortcuts that could put your data at risk.

You can expose passwords without typing them directly into AI. Suppose you upload a screenshot and ask, “Why isn’t this login working?”

Look carefully at the screenshot first.

  • Does it show your username?
  • Is the password visible?
  • Is there a QR code for account setup?
  • Are recovery codes displayed somewhere?
  • What about an authentication token or other account information?

AI tools that can analyze images may be able to read much more than the error message you wanted help understanding. Crop or redact sensitive information before uploading screenshots to an AI!

Of course, AI can still help you with passwords. For example, you can ask it makes a password strong or how passkeys work. Learn more about the dangers of password reuse and how to implement multi-factor authentication.

Those are educational questions that can benefit your understanding of cyber-safety. When the conversation involves actual account credentials, that’s when you need to draw the line.

The rule is simple: If you would not post it publicly, think carefully before giving it to AI. If it unlocks an account, do not give it to AI at all.

Passwords, PINs, recovery codes, and authentication tokens are all meant to be kept private. Therefore AI does not need any of them to help you understand cybersecurity.

Instead, use AI to learn how to protect your accounts. Use a password manager to create and protect the credentials that actually unlock them. Some jobs simply do not belong to a chatbot!