The worst passwords of 2023 are also the most common, “123456” comes in first::undefined

  • @MeekerThanBeaker
    link
    English
    111 year ago

    I think most of these are for accounts where people don’t care if they are hacked or not.

    Regardless, this should not be on the individual. The issue is with the website that allows those types of passwords to begin with. There are sites that don’t allow special characters at all. Stupid.

    • @JustAnotherRando
      link
      English
      13
      edit-2
      1 year ago

      The most infuriating thing is websites that actually limit secure passwords (e.g. “password must be between 6 and 12 characters”). Preventing longer passwords makes little sense if they’re salting and hashing; and if they’re storing the passwords in plain text (which is just about the only reason to limit the max length to anything less than what a person would reasonably remember), that’s even worse.

      • @[email protected]
        link
        fedilink
        English
        81 year ago

        There was a belief, before the advent of ubiquitous password managers, that allowing passwords to be “too long” would result in people forgetting their password more often, entering it wrong, or some combination which would increase reset requests and ultimately cause people to use worse passwords. Basically “you can’t remember a 54 character random password, and you’re gonna get pissed and switch to a six character predictable word”.

        This is now obviously a terrible line of reasoning, but it was only middling bad at the time.

        • @JustAnotherRando
          link
          English
          41 year ago

          Oh, i guess that makes some sort of sense - obviously I disagree with the conclusion, but I understand it - but it’s beyond frustrating when you think “maybe I’ll pay this bill online” and see that limit. And even if that is the reasoning for the limit, if they haven’t updated their requirements in all that time, I have little faith that they’re storing my sensitive information securely.

          • @[email protected]
            link
            fedilink
            English
            21 year ago

            I feel like most of the sites I’ve seen password limits like this on are financial in nature, where it’s all theatrics - the appearance of security takes precedence over (and in some cases comes at the expense of) actual security.

    • @systemglitch
      link
      English
      41 year ago

      Exactly, I’m not using a real password for a site I don’t care about where I have nothing to protect.

      I’m using something simple that I can type with one hand.

      Something important however? Good luck figuring that out.