26 December 23, 10:25
Quote:Each year, analysts at various Internet security companies release lists of the most used (and known) passwords. These lists are based on leaked password database data.Continue Reading
The passwords that are on these lists may act as a warning for any Internet and electronic device user. It should have the title "don't use these passwords", but is it really that simple?
Some common passwords have been used for ages and they continue to be used. Are users really resistant to improving their online security?
NordPass' Top 200 Most Common Passwords list
NordPass released a list of top 200 common passwords last month. The company states that it compiled the list "in partnership with independent researchers".
The analysis extracted passwords from a 4.3TB database that has been fed with data from publicly available sources.
The top 10 could be from any year in the past 20 years:
Mostly numbers in the top 10. The strings "admin" and "password" are common default passwords for certain devices, but they are also widely used by users.
- 123456
- admin
- 12345678
- 123456789
- 1234
- 12345
- password
- 123
- Aa123456
- 1234567890
You may wonder about some other passwords that you expected to be higher on the list. The popular "qwerty" password is on position 25, There is also "admin123" on 18, "user" on position 20 and "demo" on position 44.
All of these passwords have in common that brute force cracking runs take less than 12 seconds to find these passwords. The first password that requires a longer attack is "Eliska81". It is at position 40 and requires 3 hours to get cracked.
Another common type of password appends "@123" to a basic name. The list contains several examples of that, including "India@123" and "admin@123" as examples. These do take 3 hours to brute force as well.
...