Live data from Hacker News

25 Most Common Passwords of 2015

abitofabyte.blogspot.com

41–50 of 50 posts

Re: 25 Most Common Passwords of 2015

#41
post #15

All of our hard work convincing people to think of longer passwords has finally convinced the populace to type 'qwertyuiop' instead of 'qwerty' when they're asked to make an account for a service they don't care about. The best way to improve password quality at least looking at it from the perspective of a user with my habits is to wait to have me make an account until I actually want the service. If I have to think…

I've used 1qaz2wsx for throw-away accounts. I mean, come on... I create at least one new account a week! >:(

What annoys the hell out of me is this constant insistence on creating accounts or even connecting your social media account.

How about just making your damn service/product good to where once people are hooked in they will actually want to create the account when they are damn well ready.

Re: 25 Most Common Passwords of 2015

#43

I often either reuse a simple password or use a stupidly simple one for sites that require a signup but for which I do not care to interact with in any meaningful way. Have to create an account on some new startups app? username: newstartupname_myname password: 12345! need to sign up for a "trial" account to get access to content I probably don't even want? same thing. so while I'm sure that there are way too many pe…

The primary danger would be that you add sensitive information, forgetting that the account is weakly protected.

I've found that having a password manager compels me to have a strong password for every single site. Not having to remember anything (is this a weak password site? Did they require a number or capital?) is such a relief, and knowing that the account is as strongly protected as it can be (with respect to my control over the situation) is quite comforting.

Re: 25 Most Common Passwords of 2015

#45
I think there's still way to many things that require dedicated accounts out there, and that erodes our ability to create secure passwords.

I think I can handle 3-5 passwords on sites I use on a regular basis just fine. The next 10 sites, and I misremember things. Past that every visit that requires a login is me going through the "forgot password, request password, log into email, wait for password reset email, click link, reset password, have it slip my mind again, reset password again, log in" cycle that may take anywhere from 10-30 minutes of my time.

But having to come up with new passwords for these website makes me lazier with them. I want a chance to remember it given low repetitions, so I follow a pattern. I might not want to type a long complicated password in twice, so I make it shorter. I might start reusing it. There's only so much space in my head I'm willing to dedicate to remembering passwords and usernames, so I start to compress things, and this becomes habitual. Against all better knowledge, even some of my more important passwords become trivial to guess.

Now as someone who is running a low usage frequency website, you could say to yourself: "User error, not my problem". You could imagine a pretty world with unicorns and users who remember their passwords for your risotto blogs comment section, and that they parkour through your login experience, straight from A to B. It says one-click login on the tin, didn't it?

No,I think requiring login at all should be a conscious design decision you have to make before you ever boot up the old Apache. Is it necessary, can you offload it to third parties, or if you do it, at what point it starts being necessary. Take a sober look at whether your website is one of the 5 I'll use often enough to remember the password for, and if it isn't, keep it in mind when deciding what to put on which side of the login wall.

Re: 25 Most Common Passwords of 2015

#47
post #20

One that did catch my eye was 1qaz2wsx Take a look at your keyboard to see that one. While it has potential, it could be a little longer. It is still the strongest one from the list though. How so? It could be a 100-character string of seemingly random symbols; if it's at the top of the list, it's not a strong password.

if it's at the top of the list, it's not a strong password.

An interesting point of view that makes the whole thing a game-theoretic problem - your choice is only good as long as not too many other people chose the same.

An analogy might be that of a stock: A password (stock) is only worth 'acquiring' as long as not too many people have it.

But I believe the difference is the quantity of passwords (money) chasing sites (stocks).

A similar version of that might be a simultaneous multiplayer number guessing game where the player wins that guesses the smallest positive number no one else has guessed.

Re: 25 Most Common Passwords of 2015

#48
post #41

Earlier quoted context omitted.

I've used 1qaz2wsx for throw-away accounts. I mean, come on... I create at least one new account a week! >:(

What annoys the hell out of me is this constant insistence on creating accounts or even connecting your social media account. How about just making your damn service/product good to where once people are hooked in they will actually want to create the account when they are damn well ready.

Exactly! I've been working on my own app for a bit; once I go live I completely intend on having gradual sign-up. You'll have a session. You can use the entire app, but if you want to safe your stuff you better register ;)

Re: 25 Most Common Passwords of 2015

#50

I often either reuse a simple password or use a stupidly simple one for sites that require a signup but for which I do not care to interact with in any meaningful way. Have to create an account on some new startups app? username: newstartupname_myname password: 12345! need to sign up for a "trial" account to get access to content I probably don't even want? same thing. so while I'm sure that there are way too many pe…

Same here. If you make it a strong password that you reuse in another site, there's a danger if someone hacks into it and finds that password.
Post reply on HN