Security Now (Audio) SN 1066: Password Leakage - Zero Trust, Zero Knowledge
41 snips
Feb 25, 2026 A deep technical audit of major password managers and why feature creep can hide critical flaws. Discussions of massive personal-data leaks, ransom trends, and exposed Social Security numbers. Debate over 3D‑printer gun‑blocking bills and why those fixes are flawed. Notes on browser support changes, Russia briefly blocking the Linux kernel site, and warnings against using LLMs to generate passwords.
AI Snips
Chapters
Transcript
Episode notes
Do Not Use LLMs To Generate Passwords
- Never ask an LLM to generate passwords directly because models predict tokens rather than uniformly sample random characters.
- Irregular's testing showed repeated patterns and reused passwords from LLMs making them weaker than they appear.
Breaches Recombined Can Produce Inflated Datasets
- Large aggregated datasets can recombine past breaches into massive but noisy files with duplicates and errors.
- UpGuard found an exposed Elastic index with 2.7 billion SSN entries likely recombined from prior breaches, many redundant or invalid.
Freeze Your Credit Immediately When Possible
- Freeze your credit proactively because personal data is widely leaked and reused.
- Steve recommends freezing credit unless actively applying, citing repeated large-scale leaks and the exposed SSN dataset as evidence.
