Are you any good at creating passwords?

Jan 30, 2010 By Tim Barker

There's an interesting little study that's been done by security firm Imperva, which analyzed some 32 million passwords posted online in December by some enterprising hacker.

Imperva's analysis (www.imperva.com/docs/WP_Consum… _Worst_Practices.pdf) shows pretty much what you'd expect -- people, in general, don't take passwords all that seriously.

There's no other way to explain how 30 percent of users chose passwords with six or fewer characters -- making them quite vulnerable to brute force attacks. Or why nearly half of the users chose slang words, proper names and words found in the dictionary.

Such things are frowned upon by security experts, who say they make you an easy target.

So, just for fun, let's look at the top 10 passwords found among those 32 million samples:

1. 123456

2. 12345

3. 123456789

4. Password

5. iloveyou

6. princess

7. rockyou (the name of the site the passwords were stolen from)

8. 1234567

9. 12345678

10. abc1233

If any of these look familiar, maybe it's time to put just a little more thought into your password selection -- particularly if the in question is guarding credit card data or anything else you don't want a total stranger to know.

Explore further: New privacy battle looms after moves by Apple, Google

4.2 /5 (12 votes)
add to favorites email to friend print save as pdf

Related Stories

Tired of Passwords? Replace Them With Your Fingerprint

Sep 14, 2004

If you're like most people, you have more than a dozen passwords and user names to remember. Whether you're checking your e-mail for new messages, catching up on the news, posting to a Web discussion group, ...

So many passwords, so little memory

Apr 15, 2009

How many keys are on your keychain? I just looked at mine and counted nine keys. And that's not counting the bulky little remote control key fob that locks and unlocks my car. I've tried to consolidate my keys by making one ...

Help! How to avoid fast-moving computer worm

Jan 28, 2009

Since early January, a worm that has been referred to by several names, including "Downadup," "Kido" and "Conficker," has been infecting millions of computers around the world. The worm exploits a previously discovered vulnerability ...

Spyware poses identity-theft risk (Update)

Sep 15, 2005

A new study finds that a growing amount of Internet spyware -- programs downloaded to users' computers without their knowledge -- is designed specifically to steal personal information that could be used for identity theft. ...

Recommended for you

Say Ello to the new privacy debate on social media

Sep 29, 2014

Ello is new social networking space on the web that is receiving a lot of attention of late – so much that it's caused a few problems with the website out of action from time to time. ...

Post-Snowden, iPhone 6 encryption fans safety debate

Sep 28, 2014

Encryption technology in the iPhone 6 has taken root in a scales-of-justice debate between privacy supporters and public safety officials. Apple is using a more advanced encryption technology.

User comments : 3

Adjust slider to filter visible comments by rank

Display comments: newest first

Jimster
not rated yet Jan 31, 2010
I find the easiest way to create a very secure password as well as a way to easily remember it is to use a Chess opening in algebraic notation. For example e4Nf6e5Nd5d4 is a good start. If you want to add another layer of security you can relable the board columns with
T-U-N-A-F-I-S-H or other suitable combination of letters. For chess players these passwords are very easy to remember and have case-sensitive characters.
nevdka
not rated yet Feb 01, 2010
I've always found neighbors' cars' license plates to be a good source of passwords. Especially since I move around a lot, and most of my neighbors have gone through cars quickly...
Grave
not rated yet Mar 09, 2010
just use longer sentence as a password, its easy to remember and pretty much unhackable in reasonable timeframe even with good rainbowtables (the longest were around 30 characters long)