The top 10 awfully bad passwords people use

Many end users don't understand the need for good passwords, report shows

You might think that after nearly two decades of data breaches, identity theft and other online risks, your average end user would understand by now the importance of creating strong passwords and protecting them.

You would be wrong.

Data security firm Imperva analyzed 32 million passwords that a hacker stole from an application developer called rockyou.com, and  published a report of the findings earlier this year – including the 10 most-commonly used passwords, all of them terrible.

They are:

  1. 123456
  2. 12345
  3. 123456789
  4. Password
  5. iloveyou
  6. princess
  7. rockyou
  8. 1234567
  9. 12345678
  10. abc123

Entry No. 7, "rockyou," is the name of the Web site for which the users created the password. Their Amazon.com and Audible.com passwords are probably "amazon" and "audible," respectively.

Nearly half of the users created easily guessable passwords, including names, dictionary words and strings of consecutive numbers, according to the report. The most common password found was "123456."

"Everyone needs to understand what the combination of poor passwords means in today's world of automated cyberattacks: With only minimal effort, a hacker can gain access to one new account every second — or 1,000 accounts every 17 minutes," said Amichai Shulman, Imperva's chief technology officer, in a written statement that accompanied the release of the findings. "The data provides a unique glimpse into the way that users select passwords and an opportunity to evaluate the true strength of passwords as a security mechanism. Never before has there been such a high volume of real-world passwords to examine."

Download the full report.

 

 

About the Author

Michael Hardy is the news editor of Federal Computer Week. Follow him on Twitter: @MichaelHardyFCW.

Reader Comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Comment:
Please type the letters/numbers you see above

Amber Corrin's Inside DOD Blog

Webcast

  • Using Big Data Tools to Manage the Deluge of ISR Data

    Defense IT professionals and other data-driven agencies are turning to new methods to capture, process and analyze new volumes of data and insure they are maximizing its value. This webinar will explore how cloud tools and infrastructures have created new opportunities to share, collaborate and accelerate decision making across agencies and geographic regions. A Government expert will explore the broader ISR situation and challenge as it exists in the military today, and how Big Data tools can be used to tame that data and make it usable to the warfighter on a real-time or near-real-time basis. Read more