Web Gangsta – Web Watch

Your Password Sucks

Jimmy Ruska was able to obtain some hacked database files from MySpace, phpBB, and Singles.org. 

These files contained basic user and password information, resulting in 116,782 passwords being available for analysis.  These files were from early 2009.

Here is a quick look at some of the information that Jimmy found about what THE MOST COMMON PASSWORDS ARE:

Singles.org

  1. 123456
  2. jesus
  3. password
  4. love
  5. 12345678

phpBB

  1. 123456
  2. password
  3. phpBB
  4. qwerty
  5. 12345

MySpace

  1. password1
  2. abc123
  3. password
  4. iloveyou1
  5. iloveyou2

When all three databases were combined, the top passwords from the combined databases were:

  1. 123456
  2. password
  3. phpbb
  4. qwerty
  5. 12345

Jimmy did some further digging into the data.  Generally speaking, passwords were most often 6 characters in length (26.99% of the time), followed closely by 8 character and 7 character length passwords.  10 characters were used just 5.06%, and anything over 10 each occured less than 1% of the time.

Jimmy has a fascination with passwords, as he indicates by also including a LIST OF MOST COMMONLY USED PASSWORDS BY TYPE, which is a great list to use to know what to stay away from when deciding what password to use.  As Jimmy states, people spend hours coming up with the ideal username, but spend just minutes coming up with a password. 

Among those items to stay away from in choosing a password:

  1. 123456, 123, 123123, 01234, 2468, 987654, or any other simply number construction
  2. 123abc, abc123, 246abc, etc.  See #1.
  3. Your first name
  4. Your favorite band
  5. Your favorite song
  6. Your first initial and last name (jdoe, jsmith)
  7. qwerty, asdf, etc.  See #1.
  8. Your favorite cartoon character
  9. Your favorite sport or sports star
  10. Your country of origin
  11. Your city of origin
  12. A password that consists of all numbers (birthday, anniversary, etc)
  13. Some word that can be found in a dictionary
  14. Two such dictionary words
  15. Anything from #1-#14 spelled backwards
  16. aaa, eee, fff, or other repeat key combinations

So how do you pick a good password?  Here are some handy tips: