Live data from Hacker News

The 25 worst passwords of 2013: 'password' gets dethroned

pcworld.com

11–13 of 13 posts

Re: The 25 worst passwords of 2013: 'password' gets dethroned

#11
post #2

That's flawed logic. Most of the analysis comes from the Adobe leakage, and arguably a large share of users there didn't care about this service and used an easy and weak password. It would be much more interesting to have stats from active gmail accounts or bank accounts, for instance.

That would surely explain why "photoshop" and "adobe123" are so high.

Article is garbage: sample is clearly biased.

Re: The 25 worst passwords of 2013: 'password' gets dethroned

#12
post #8

Passwords are bullshit and it is our failure as an industry: we should be moving away from passwords.

What alternative is there? When it comes to authentication, there are only a few categories: 1. Something you know: password, secret question, mother's maiden name. These can be forgotten. If the information is generated by the user, it has the potential to be something easily guessed. 2. Something you have: SSH key, GPG key, RSA token, Yubikey, Google Authenticator. These can be quite secure, but hard to use. Losing…

You can split 2. into several pieces which will allow you to recover if you lose something. Imagine you have a SSH key, an authenticator token and a printed physical QR code and you can restore either of that if you have both of the rest.
Post reply on HN