Live data from Hacker News

25 Most Common Passwords of 2015

abitofabyte.blogspot.com

31–40 of 50 posts

Re: 25 Most Common Passwords of 2015

#34
post #21

The author, some of the comments here and especially the author of the Gizmodo article seem to lament the fact that passwords aren't stronger. I have no idea about whether or not that is justified, but a list of the most common passwords is in no way reflective of average password strengths. A good password is probably unique in the world so by definition the only passwords on this list are those that are trivially e…

This is a good point. If these are each used by 2 people, it's not very interesting. It's sort of implied by the attention these stories get that the problem is much bigger than that, but I agree the story is incomplete without the magnitudes. And for the rest of us, we should care about the _trend_ of the % population using common passwords. In order to be safe, you probably need to stay above some constant level that is "good enough" for any hacker trying patterns or brute forcing. As the bottom gets more secure after reading articles like this or adopting password managers, we all need to step up our game. The first to go will be people who do things like:

- put a capital letter first and only first when a capital letter is required

- put a special character last and only last when a special character is required

- put a number next to last and only next to last when a number and a special character are both required

These will be the next patterns tried after the most common passwords, dictionary attacks, etc. -- and if you stay ahead of _these_ people then you'll be good for a while.

Re: 25 Most Common Passwords of 2015

#36
I wish they would include how many times each password was used. Those top 25 representing 50,000 out of a million passwords means something very different than if they represent just 1,000 out of a million.

Comparing the proportion of the million passwords that are accounted for by the top 25 (and top 100, top 1000, etc.) year to year also gives a much better measure of whether public behavior is improving than just seeing if the top 25 are obviously poor passwords.

Re: 25 Most Common Passwords of 2015

#37
post #20

One that did catch my eye was 1qaz2wsx Take a look at your keyboard to see that one. While it has potential, it could be a little longer. It is still the strongest one from the list though. How so? It could be a 100-character string of seemingly random symbols; if it's at the top of the list, it's not a strong password.

It's not. It looks "randomish" to humans, but it's not actually any different from 12345678.

Re: 25 Most Common Passwords of 2015

#38
> Hopefully, 2016 will bring much stronger passwords to the general public, but going off of previous years, I have my doubts.

Hopefully, 2016 will bring better methods of authentication to the general public, but going off of previous years, I have my doubts.

Re: 25 Most Common Passwords of 2015

#39
post #20

One that did catch my eye was 1qaz2wsx Take a look at your keyboard to see that one. While it has potential, it could be a little longer. It is still the strongest one from the list though. How so? It could be a 100-character string of seemingly random symbols; if it's at the top of the list, it's not a strong password.

It might be a 'strong' password according to these stupid 'password enforcers' on websites which think they're smart enough to decide for us.

Not quite. That password would be "1qaz@WSX".

You see, you need a number and a special character, a lowercase letter and an uppercase character.

Re: 25 Most Common Passwords of 2015

#40
post #20

One that did catch my eye was 1qaz2wsx Take a look at your keyboard to see that one. While it has potential, it could be a little longer. It is still the strongest one from the list though. How so? It could be a 100-character string of seemingly random symbols; if it's at the top of the list, it's not a strong password.

It might be a 'strong' password according to these stupid 'password enforcers' on websites which think they're smart enough to decide for us.

"Your 32 completely random characters doesn't contain enough special symbols, and is thus insecure."
Post reply on HN