Menu DaniWeb
Log In Sign Up
  • Read
  • Contribute
  • Meet
  1. Forums
  2. Hardware and Software
  3. Networking
  4. News Stories
  5. News Story

Crappiest passwords are most popular

17 Years Ago happygeek 0 Tallied Votes 305 Views Share

Ever wondered what the most popular passwords being used are? Ever wondered what the crappiest, most insecure passwords being used are? Hey, you are in luck as it seems the two lists are exactly the same. The What's My Pass 'Top 500 Worst Passwords of All Time' list makes for interesting, if sometimes rather offensive (you have been warned), reading.

So I have stripped out the expletives and compiled the top 20 most popular and crappy passwords to give you something to ponder upon as we approach the end of the year. Just please don't tell me that you use any of these!

  1. 123456
  2. password
  3. 12345678
  4. 1234
  5. 12345
  6. dragon
  7. qwerty
  8. 696969
  9. mustang
  10. letmein
  11. baseball
  12. master
  13. michael
  14. football
  15. shadow
  16. monkey
  17. abc123
  18. pass
  19. 6969
  20. jordan

The only real surprise is that 'sex' does not make the top 500 list at all. The closest variant being sexy at number 44 and then sexsex at 64.

So go on then, do share, what is the crappiest password you have ever stumbled upon? Remember, keep it clean!

cybersecurity
About the Author
Member Avatar for happygeek
happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A freelance technology journalist for 30 years, I have been a Contributing Editor at PC Pro (one of the best selling computer magazines in the UK) for most of them. As well as currently contributing to Forbes.com, The Times and Sunday Times via Raconteur…

Dani AI

Generated 9 Months Ago

A short expert summary and practical fixes to sit above this thread.

The thread (started by and followed by notes from , , , and others) illustrates a persistent reality: people keep choosing memorable-but-guessable credentials and those choices quickly end up in breach corpuses that attackers reuse. Large, aggregated breach lists and the public “pwned passwords” services make credential-stuffing and offline cracking effective—treat any common or reused password as already compromised. (haveibeenpwned.com)

What to do as an individual: stop trying to invent memorable “clever” mutations and use tools and techniques that scale. Use a reputable password manager to generate and store unique, long credentials; prefer memorable passphrases (NCSC’s “three random words” approach) or long random strings; and enable multi‑factor authentication on high‑value accounts. Don’t paste live, active passwords into unknown sites or untrusted forms—use integrated APIs or your password manager’s breach‑check features instead. (nicybersecuritycentre.gov.uk)

What to do as a system owner or admin: block known-bad passwords and breached values rather than forcing arbitrary complexity rules; permit long passphrases and allow paste; avoid periodic forced resets except on evidence of compromise; implement rate limiting/account lockout and logging to defeat online guessing; and store credentials with modern slow hashes (Argon2id/scrypt/bcrypt as appropriate) with salts and appropriate work factors. These are explicit recommendations in modern guidance. (pages.nist.gov)

Quick checklist (actionable):

  1. Deploy a breached-password blacklist (or integrate Pwned Passwords).
  2. Require unique credentials and promote password managers + 2FA.
  3. Harden storage with Argon2id/scrypt and rotate hashing parameters when needed.
  4. Educate users about hints, reuse, and not exposing passwords in hints or help fields.
    When those four items are in place, the kinds of weak choices discussed in this thread become far less risky. (haveibeenpwned.com)
Member Avatar for Thinka
Thinka 40 Posting Whiz Team Colleague
17 Years Ago

I've worked with someone whose password was "london". Unsurprisingly, this was at a company in the City of, you guessed it, London.

Member Avatar for kanaku
kanaku 60 Posting Whiz
17 Years Ago

Sex probably didn't make it because it's too short (the word)...

I haven't encountered someone with an 'easy' password. My friends could be security freaks...

Member Avatar for tiger86
tiger86 16 Posting Pro
17 Years Ago

I have encountered passwords as simple as flower or the persons name and have had to change them and inform the person to keep the server I protect secure.

Member Avatar for scru
scru 909 Posting Virtuoso Featured Poster
17 Years Ago

My daniweb password is 12345. I don't see what the big deal is.

Member Avatar for Thinka
Thinka 40 Posting Whiz Team Colleague
17 Years Ago

scru, I don't know how many people who read this blog will be tempted to use that information, but I hope none.

It reminds me of when Jeremy Clarkson posted his account details in the newspaper, and promptly had £500 deducted from his account...

Member Avatar for Whabligone
Whabligone 0 Newbie Poster
17 Years Ago

I had a customer who used the trademark on the monitor as their password "syncmaster"

Member Avatar for fire_munki
fire_munki 0 Newbie Poster
17 Years Ago

I've found the exact password in the hint section for customers before, very helpful.

Reply to this topic
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.

Sign Up — It's Free!
Recommended Topics
  • Member Avatar Top 10 Passwords Revealed 1
  • Member Avatar SQL failure exposes plain text passwords 2
  • Member Avatar IT Certifications, that are safe to get early? 4
  • Member Avatar The high price of fake software 0
  • Member Avatar Domain headache 4
  • Member Avatar REVIEW: Logio Secure Password Organizer 1
  • Member Avatar Help! 2
  • Member Avatar SF Password Hijack Highlights Importance of Process in City, State IT 1
  • Member Avatar Internet Gateway Stuck! 5
  • Member Avatar The growing threat of keyloggers 1
  • Member Avatar Cannot Share External Hard Drive on Windows Network 2
  • Member Avatar Accused Network Administrator Still In Jail 0
  • Member Avatar Malware Problem 4
  • Member Avatar Japanese break virus writing arrest duck 4
  • Member Avatar Host Headers with IIS 5
  • Member Avatar ATM security leaves customers vulnerable to hackers 5
  • Member Avatar Joe "Zonker" Brockmeier Discusses openSUSE 11.1 0
  • Member Avatar Cult of the Dead Cow releases Google hacking tool 1
  • Member Avatar Mac OS X Leopard Gets Forty One New Spots 0
  • Member Avatar Bonkers Boris, Mad McKinnon, Osama Bin-Laden, Barack Obama and Little Green Men From Mars 2
Not what you need?

Reach out to all the awesome people in our networking community by starting your own topic. We equally welcome both specific questions as well as open-ended discussions.

Start New Topic
Topics Feed
Reply to this Topic
Edit Preview

Share Post

Insert Code Block

  • Forums
  • Forum Index
  • Hardware & Software
  • Programming
  • Digital Media
  • Community Center
  • Recent
  • Recommended Topics
  • Newest Topics
  • Latest Topics
  • Latest Posts
  • Latest Comments
  • Top Tags
  • Tools
  • Writing
    • Start New Topic
    • Markdown Syntax
    • Newsletter Archive
  • Social
    • Top Members
    • Meet People
  • APIs
    • Connect API
    • Forum API Docs
    • Topics Feed
  • Resources
  • Community Rules
  • DaniWeb Premium
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Legal
  • Terms of Service
  • Privacy Policy
© 2026 DaniWeb® LLC
© 2026 DaniWeb® LLC
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Terms of Service
  • Privacy Policy