The worst passwords of 2023 are also the most common, “123456” comes in first::undefined

  • @brygphilomena
    link
    English
    891 year ago

    only one – “theworldinyourhand” – is virtually uncrackable. It is the number 173 most common password and would take centuries to guess using brute force.

    Not anymore. That would get moved towards the top of the rainbow table now.

    • @[email protected]
      link
      fedilink
      English
      301 year ago

      Pass phrases for the passwords you have to type by hand, automatically generated passwords for the things that can autofill from a password manager, MFA for everything that supports it.

      Anything less or any password reuse is just asking for trouble.

      • @JustAnotherRando
        link
        English
        131 year ago

        Yeah, using a pass phrase makes it much easier to remember on top of being more secure. But users should introduce at least a bit more complexity than that example (all lower case letters isn’t great). This1sComplexButMemorable! Is an easy example of how you can just make up a relevant sentence to what you’re using, include a range of character types for complexity and to meet requirements, and you’re good to go. Plus if you make it relevant to what you’re logging into, you’re less likely to be tempted to reuse the pass.

        • @brygphilomena
          link
          English
          51 year ago

          ThisIsMyMotherfuckingHotmailPassword!

          Is an incredibly secure password for Hotmail. And super memorable.

      • JohnEdwa
        link
        fedilink
        English
        7
        edit-2
        1 year ago

        OTOH passphrases are so rarely used that other than a handful of common examples that would already be in a word list such as CorrectHorseBatteryStaple, it would be rather unlikely for anyone to bother even trying unless they are specifically trying to crack a specific password.

        So maybe don’t use a plain four word english passphrase as the admin login, but if your facebook password is ZuckerbergSucksFlaccidCock, 'tis probably fine.

        • 𝚝𝚛𝚔
          link
          fedilink
          English
          31 year ago

          ZuckerbergSucksFlaccidCock

          Is that better or worse than an erect one, from an insult point of view?

    • @toasteecup
      link
      English
      281 year ago

      123456, that’s the same password that I have on my luggage! Set a course for druidia and change the password on my luggage

  • Square Singer
    link
    fedilink
    English
    391 year ago

    They got this data from password leaks. Crappy sites that force you to create an unnecessary account for basic usage are arguebly more often part of password leaks.

    So it’s not a surprise that a huge amount of leaked accounts have passwords like 123456, because that’s exactly the right kind of password for a throwaway account that you’ll never need again. In the best case coupled to a trashmail email account.

  • Bernie Ecclestoned
    link
    fedilink
    English
    27
    edit-2
    1 year ago

    Apparently, people creating new accounts seem to assume the word (password) in the box in light gray font is a suggestion rather than a label.

    lol

  • @edgemaster72
    link
    English
    221 year ago

    No mention of descending numbers, looks like 654321 is still safe. Not that uh, I, would have any particular worry about that one, nope.

    eyes dart back and forth rapidly

    • @[email protected]
      link
      fedilink
      English
      91 year ago

      Just waiting for the day when they start calling out those of us who make all our passwords easy to type with one hand.

      • @AbidanYre
        link
        English
        51 year ago

        All your passwords, or only the ones for certain websites?

      • @taiyang
        link
        English
        31 year ago

        Funny, I thought only I did that. Looks like a boss when you login to a system with just one hand and at lightning fast speeds.

  • Dem Bosain
    link
    fedilink
    English
    201 year ago

    Good old ]yèî̾ÌP®åÙyJàºséí³Òò&ÚÀxÁõÝÞ/ÍÔ9~B6Æ¿Üïd`ÛÝm®@. Nobody ever guesses that.

  • @NOT_RICK
    link
    English
    191 year ago

    Hunter2, still haven’t been hacked (in the past few weeks)

    • @samus12345
      link
      English
      8
      edit-2
      1 year ago

      That’s amazing, I’ve got the same combination in my username!

  • @MeekerThanBeaker
    link
    English
    111 year ago

    I think most of these are for accounts where people don’t care if they are hacked or not.

    Regardless, this should not be on the individual. The issue is with the website that allows those types of passwords to begin with. There are sites that don’t allow special characters at all. Stupid.

    • @JustAnotherRando
      link
      English
      13
      edit-2
      1 year ago

      The most infuriating thing is websites that actually limit secure passwords (e.g. “password must be between 6 and 12 characters”). Preventing longer passwords makes little sense if they’re salting and hashing; and if they’re storing the passwords in plain text (which is just about the only reason to limit the max length to anything less than what a person would reasonably remember), that’s even worse.

      • @[email protected]
        link
        fedilink
        English
        81 year ago

        There was a belief, before the advent of ubiquitous password managers, that allowing passwords to be “too long” would result in people forgetting their password more often, entering it wrong, or some combination which would increase reset requests and ultimately cause people to use worse passwords. Basically “you can’t remember a 54 character random password, and you’re gonna get pissed and switch to a six character predictable word”.

        This is now obviously a terrible line of reasoning, but it was only middling bad at the time.

        • @JustAnotherRando
          link
          English
          41 year ago

          Oh, i guess that makes some sort of sense - obviously I disagree with the conclusion, but I understand it - but it’s beyond frustrating when you think “maybe I’ll pay this bill online” and see that limit. And even if that is the reasoning for the limit, if they haven’t updated their requirements in all that time, I have little faith that they’re storing my sensitive information securely.

          • @[email protected]
            link
            fedilink
            English
            21 year ago

            I feel like most of the sites I’ve seen password limits like this on are financial in nature, where it’s all theatrics - the appearance of security takes precedence over (and in some cases comes at the expense of) actual security.

    • @systemglitch
      link
      English
      41 year ago

      Exactly, I’m not using a real password for a site I don’t care about where I have nothing to protect.

      I’m using something simple that I can type with one hand.

      Something important however? Good luck figuring that out.

  • @dhork
    link
    English
    91 year ago

    Hey, how did you guess the password on my luggage?

    • @tpihkal
      link
      English
      71 year ago

      Whoa, holup. We can use numbers and letters‽

    • r00ty
      link
      fedilink
      61 year ago

      Everyone knows the correct test credentials are test/test. Even then, that’s only if they don’t allow blank/no password.