Tech●●●●●Difficulty 1 of 5

Why are most passwords so easy to guess?

In 2019 the most popular password in a huge pile of breached accounts was "123456", used 23.2 million times.

▶ Start the story

Most passwords are easy to guess because people are predictable. In 2019 the UK's National Cyber Security Centre studied public databases of breached accounts, and the most popular password was "123456", used in 23.2 million of them. "qwerty" and "password" were both in the top five. An attacker does not need to be clever, only to try the favourites first.

Most common passwords in breached accounts (2019)

million uses

Bar chart: Most common passwords in breached accounts (2019). (million uses)
Times used
12345623.2 million uses
1234567897.7 million uses
qwerty3.8 million uses
password3.6 million uses
11111113.1 million uses
UK NCSC analysis of public breach databases.

Passwords people think are clever are not much safer. Humans follow patterns, such as a number at the end or a 3 swapped for an E. Those habits are well known, and password-guessing programs come loaded with long lists of common passwords, including real ones from past breaches, plus the usual small modifications of them.

Strength is measured in "bits of entropy", and every extra bit doubles the number of guesses an attacker needs. A study of half a million users put the average human-chosen password at about 40.5 bits. The US and UK security agencies now recommend long, memorable passwords over short, complicated ones, and passphrases of ordinary words like "cassette lava baby" have gained traction as advice.

The other great weakness is reuse. When one site leaks its passwords, attackers try the same pairs on other sites. This is called credential stuffing, and with a hit rate one expert put at up to 2 percent, a million stolen logins can open about 20,000 accounts. That is why security experts recommend a distinct password for every account.

Quiz me

0/3

  1. 1.Why did sites stop forcing people to include capitals, digits and symbols?
  2. 2.What does one extra bit of entropy do to the work of an attacker?
  3. 3.Why can credential stuffing work without any password guessing?

Recap

A password fails when it is common, patterned, or reused, which is why experts advise long passwords, different for every account.

💡 A trick to remember it · Long beats strange, and one lock per key: a long passphrase for each door, never one key for all.

Surprising fact · "123456" appeared in 23.2 million breached passwords.

Sources (2)

No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.

  1. [1]Password strength · Wikipedia
  2. [2]Credential stuffing · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗