Page 1 of 2 [ 19 posts ]  Go to page 1, 2  Next

tweety_fan
Veteran
Veteran

User avatar

Joined: 2 Oct 2007
Age: 39
Gender: Female
Posts: 3,555

22 Jan 2014, 12:06 am

http://www.theage.com.au/digital-life/c ... 31889.html

The number sequence "123456" has overtaken "password" as the most common worst password among internet users, an online security firm says.

Releasing its annual Worst Passwords list, SplashData, whose company markets password management apps, said it was the first time "password" had lost its number-one position, changing places with its numerical rival.

In third place was 12345678, unchanged from 2012, while "qwerty" and abc123 came in fourth and fifth; "iloveyou" climbed two spots to number nine.

Swinging the results, SplashData said, was a major security breach involving Adobe software that laid bare the widespread use of weak passwords among users of such Adobe products as Photoshop.
Advertisement

"Seeing passwords like 'adobe123' and 'photoshop' on this list [for the first time] offers a good reminder not to base your password on the name of the website or application you are accessing," said SplashData chief executive Morgan Slain.

Like other password experts, SplashData encouraged internet users to opt for "passphrases" – a collection of random words, numbers and characters, such as "smiles_like_skip?" – that are easy to remember, but harder for online scam artists to crack.

Sydney-based security expert Ty Miller, of Threat Intelligence, said the results didn't surprise him.

"From memory, '123456' has been one of the most common passwords for a long time," he said.

He said it was important to remember what SplashData's results were based on. If they were based on leaked passwords from breaches of prominent websites like Adobe and others then they were likely passwords many people used as disposable ones for non-sensitive information.

"With sites like social networks you'll find '123456' is a common password, whereas if you go to common compromised internal corporate networks you'll actually find that 'password1' and 'welcome1' are both extremely common and far more common than '123456' because of password policies."

Such passwords were used, he said, because they were easy to remember.

"That's probably the main reason why people use them. The other thing I notice when I ask people about these sort of things is that they tend to have weak passwords by choice; ones they don't care if they are compromised," he said.

"So in breaches like in the Adobe hack that happened late last year, those sort of sites people don't really care about and therefore they use weak passwords that they wouldn't use on their email so that if they do get hacked they're only losing a junk password that they don't really care about."

Read more: http://www.smh.com.au/digital-life/cons ... z2r6JJHChB



cyberdad
Veteran
Veteran

User avatar

Joined: 21 Feb 2011
Age: 56
Gender: Male
Posts: 34,284

22 Jan 2014, 12:57 am

I thought passwords are encrypted for protection? how did they get this data?



TallyMan
Veteran
Veteran

User avatar

Joined: 30 Mar 2008
Gender: Male
Posts: 40,061

22 Jan 2014, 3:12 am

Phew! Looks like my password is a good one then: 987654321


_________________
I've left WP indefinitely.


GGPViper
Veteran
Veteran

User avatar

Joined: 23 Sep 2009
Gender: Male
Posts: 5,880

22 Jan 2014, 4:57 am

Also nice to know that "god" is still safe. I almost thought I was in trouble... What a relief... :D



Jono
Veteran
Veteran

User avatar

Joined: 10 Jul 2008
Age: 43
Gender: Male
Posts: 5,606
Location: Johannesburg, South Africa

23 Jan 2014, 5:35 am

GGPViper wrote:
Also nice to know that "god" is still safe. I almost thought I was in trouble... What a relief... :D


You chose "god" as a password?



GGPViper
Veteran
Veteran

User avatar

Joined: 23 Sep 2009
Gender: Male
Posts: 5,880

23 Jan 2014, 8:00 am

Jono wrote:
GGPViper wrote:
Also nice to know that "god" is still safe. I almost thought I was in trouble... What a relief... :D

You chose "god" as a password?

[youtube]http://www.youtube.com/watch?v=0Jx8Eay5fWQ[/youtube]



CockneyRebel
Veteran
Veteran

User avatar

Joined: 17 Jul 2004
Age: 49
Gender: Male
Posts: 113,565
Location: Stalag 13

23 Jan 2014, 10:14 am

I think abc123 is a real keeper. :lol:


_________________
Who wants to adopt a Sweet Pea?


cyberdad
Veteran
Veteran

User avatar

Joined: 21 Feb 2011
Age: 56
Gender: Male
Posts: 34,284

23 Jan 2014, 4:03 pm

If you add a zero like 0123456 then that would really stump any hardcore hacker...



WillMcC
Veteran
Veteran

User avatar

Joined: 16 Mar 2007
Age: 40
Gender: Male
Posts: 546
Location: Florida

25 Jan 2014, 10:02 am

I think it's time to change the combination on my luggage!

[youtube]http://www.youtube.com/watch?v=a6iW-8xPw3k[/youtube]


_________________
"Tongue tied and twisted, just an earth-bound misfit, I" - Pink Floyd
(and then the tower cleared me for take off)


Fnord
Veteran
Veteran

User avatar

Joined: 6 May 2008
Age: 67
Gender: Male
Posts: 59,893
Location: Stendec

25 Jan 2014, 11:24 am

I didn't see "Con5u6stant1ati0n" on the list. It's what I use on a certain website devoted to Roman Catholicism.

They'll never figure that one out.



TallyMan
Veteran
Veteran

User avatar

Joined: 30 Mar 2008
Gender: Male
Posts: 40,061

25 Jan 2014, 2:55 pm

Fnord wrote:
I didn't see "Con5u6stant1ati0n" on the list. It's what I use on a certain website devoted to Roman Catholicism.

They'll never figure that one out.


Yeah, I just tried it and it let me login; but like you say, nobody else will ever guess it. :P


_________________
I've left WP indefinitely.


TallyMan
Veteran
Veteran

User avatar

Joined: 30 Mar 2008
Gender: Male
Posts: 40,061

25 Jan 2014, 3:00 pm

Just remembered an incident on WP. Everyone warns not to use the name of your pet as a password - well there was a pet thread on here a couple of years ago and people were stating the names of their pets... and you guessed it, one of the members got her WP account hacked and she lost control of it. The member started posting "unusual" sexual stuff in the Adult forum. :lol: Funny side aside, using a pet name for password is dumb, posting the name of that pet is double dumb.


_________________
I've left WP indefinitely.


wozeree
Veteran
Veteran

User avatar

Joined: 23 Aug 2013
Age: 62
Gender: Female
Posts: 2,344

25 Jan 2014, 5:46 pm

At work not long ago, I had a problem and they had to reset my password and give me a temp. The temp wasn't 12345, but it wasn't much less inane. I still haven't changed it. Better do that Monday!



AnonymousAnonymous
Veteran
Veteran

Joined: 23 Nov 2006
Age: 34
Gender: Male
Posts: 70,206
Location: Portland, Oregon

25 Jan 2014, 7:14 pm

Using names of characters from books, TV shows, and movies as passwords are just as dumb!


_________________
Silly NTs, I have Aspergers, and having Aspergers is gr-r-reat!


MelissaCho
Yellow-bellied Woodpecker
Yellow-bellied Woodpecker

User avatar

Joined: 17 May 2011
Age: 32
Gender: Female
Posts: 70

25 Jan 2014, 7:52 pm

cyberdad wrote:
If you add a zero like 0123456 then that would really stump any hardcore hacker...

Yeah, if that person was two!



Solitudinarian
Snowy Owl
Snowy Owl

User avatar

Joined: 14 Dec 2013
Age: 52
Gender: Male
Posts: 154

25 Jan 2014, 9:15 pm

This is why more and more sites are forcing people to pick obscure passwords with at least one number, one special character, one Chinese character, one ancient Egyptian hieroglyph, and one cuneiform rune.