Guess the dumbass password

newsguy 1 Tallied Votes 454 Views Share

I have a lot of passwords to get me onto various online sites and services, but I only need to remember one: the complex and hard to crack one that unlocks my encrypted password store. Not everyone is as paranoid as I am it seems, and many fall neatly into the dumbass category if a recent analysis of 32 million consumer passwords is anything to go by.

A data security company called Imperva undertook a detailed analysis of breached consumer passwords, and the very fact that they ended up in the 32 million breached passwords database suggests that they were not brilliant to start with. However, to climb to the very top of that list by way of being the most 'popular' and hence most commonly cracked is a true measure of dumbassness.

And so, without further ado, are the top ten most commonly used dumbass passwords to be avoided when signing up for social networking or e-commerce sites:

  1. 123456
  2. 12345
  3. 123456789
  4. Password
  5. iloveyou
  6. princess
  7. rockyou
  8. 1234567
  9. 12345678
  10. abc123

“Everyone needs to understand what the combination of poor passwords means in today’s world of automated cyber attacks: with only minimal effort, a hacker can gain access to one new account every second—or 1000 accounts every 17 minutes,” explained Imperva’s CTO Amichai Shulman. “The data provides a unique glimpse into the way that users select passwords and an opportunity to evaluate the true strength of passwords as a security mechanism. Never before has there been such a high volume of real-world passwords to examine.”

According to the analysis, nearly 50% of users used names, slang words, dictionary words or trivial passwords (consecutive digits, adjacent keyboard keys, and so on). Dumbass! But the list should come as no real surprise, our award winning security writer here on DaniWeb warned about the crappiest passwords just over a year ago and back then many of the same dumbass passwords showed up in his top 20 list.

Dani AI

Generated

As points out, breached-password lists mostly show predictable, reused choices. Rather than just noting how bad that looks, the practical question is how to stop the pattern. 's pointer to the ongoing thread is useful for community tips; the following focuses on concrete, low-effort changes that reduce risk dramatically.

A password manager is the single most effective change: it makes unique, high-entropy passwords practical at scale and removes the need to memorize site-specific strings. The master secret for the vault should be a long passphrase (think 16+ characters or several random words), memorized only and not reused elsewhere. Enable multi-factor authentication for the manager and for every critical account; where possible prefer hardware-backed factors (U2F/FIDO2) for top-value services. Treat security questions like passwords: make answers long, unique, or store them in the manager.

Device and recovery hygiene matter as much as password choice. Keep the OS and password-manager app updated, enable full-disk encryption and a secure device lock, and maintain an encrypted offline backup of the vault. If cloud sync is used, confirm it is end-to-end encrypted. Be alert to phishing—credential theft via fake login prompts is a common bypass of strong passwords and MFA.

If a breach is suspected, act quickly: change the exposed credential and any other account that used it, enable or strengthen MFA, revoke active sessions, and rotate recovery options. Run periodic audits (built-in password-health checks work well) and prioritize rotation for reused or short passwords. Small, consistent habits—unique passwords, a strong master passphrase, MFA, and device hygiene—remove most of the value attackers get from leaked lists.

Salem 6,009 Posting Sage

Try to keep up http://www.daniweb.com/forums/thread254398.html
We've been discussing this for a week.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.