Live data from Hacker News

25 Most Common Passwords of 2015

abitofabyte.blogspot.com

21–30 of 50 posts

Re: 25 Most Common Passwords of 2015

#21
The author, some of the comments here and especially the author of the Gizmodo article seem to lament the fact that passwords aren't stronger. I have no idea about whether or not that is justified, but a list of the most common passwords is in no way reflective of average password strengths. A good password is probably unique in the world so by definition the only passwords on this list are those that are trivially easy to come up with. A more interesting statistic, I think, is what percentage of the world's passwords is '123456'.

Re: 25 Most Common Passwords of 2015

#22
post #15

All of our hard work convincing people to think of longer passwords has finally convinced the populace to type 'qwertyuiop' instead of 'qwerty' when they're asked to make an account for a service they don't care about. The best way to improve password quality at least looking at it from the perspective of a user with my habits is to wait to have me make an account until I actually want the service. If I have to think…

I've used 1qaz2wsx for throw-away accounts. I mean, come on... I create at least one new account a week! >:(

Re: 25 Most Common Passwords of 2015

#24
This is a well studied area and never a surprise. What I haven't seen is a list of common passphrases or common android swipe patterns or common iphone PINs. Is anyone working on this stuff?

Its also 100% shameful that I can't just shove this list into Active Directory and deny these passwords to end users. I can turn on complexity or length, but nothing else. So today's "password" will be tomorrow's "tobeornottobe" once we all migrate to passphrases/12+ minimum character passwords.

Also this is blogspam citing other blogspam. The source is SplashData and they release this analysis every year.

Re: 25 Most Common Passwords of 2015

#25
post #9

Reminds me every year that i should change my password to "INVALID" and everytime i try to login with the wrong password, i get a nice reminder. "Wrong Password - Your password is invalid" slow clap

That's a great idea: Take the error message and make that the entire password.

lol you might get into trouble if they change the error message in the meantime!

Re: 25 Most Common Passwords of 2015

#26
post #20

One that did catch my eye was 1qaz2wsx Take a look at your keyboard to see that one. While it has potential, it could be a little longer. It is still the strongest one from the list though. How so? It could be a 100-character string of seemingly random symbols; if it's at the top of the list, it's not a strong password.

It might be a 'strong' password according to these stupid 'password enforcers' on websites which think they're smart enough to decide for us.

Re: 25 Most Common Passwords of 2015

#27
I guess the key is (pun not intended) is stolen passwords and not systems that have not been setup because I bet particularly wifi and various systems "guest", "admin" and "demo" would be high up on the list.

Re: 25 Most Common Passwords of 2015

#28
The thing that drives me crazy about sequential passwords like 1234567890 and qwerty is how obvious it looks when typing it out.

Don't you want to at least provide the illusion of security? And even if you have no concerns about the account being compromised, are you really able to write "qwerty" faster than your first name?

Re: 25 Most Common Passwords of 2015

#29

This is a well studied area and never a surprise. What I haven't seen is a list of common passphrases or common android swipe patterns or common iphone PINs. Is anyone working on this stuff? Its also 100% shameful that I can't just shove this list into Active Directory and deny these passwords to end users. I can turn on complexity or length, but nothing else. So today's "password" will be tomorrow's "tobeornottobe"…

Yeah I just Googled those and they're all available.

Denying passwords would just lead to adding 1 to the end and calling it a day. We shouldn't really put any limitations on passwords users use.

Re: 25 Most Common Passwords of 2015

#30
post #15

All of our hard work convincing people to think of longer passwords has finally convinced the populace to type 'qwertyuiop' instead of 'qwerty' when they're asked to make an account for a service they don't care about. The best way to improve password quality at least looking at it from the perspective of a user with my habits is to wait to have me make an account until I actually want the service. If I have to think…

I'm not sure what this list is trying to accomplish but the problems with it are 1) it doesn't acknowledge that these are unlikely to be important passwords and 2) there's little indication this is much of an attack vector, if any at all.
Post reply on HN