Why are most passwords so easy to guess?
In 2019 the most popular password in a huge pile of breached accounts was "123456", used 23.2 million times.
▶ Start the storyMost passwords are easy to guess because people are predictable. In 2019 the UK's National Cyber Security Centre studied public databases of breached accounts, and the most popular password was "123456", used in 23.2 million of them. "qwerty" and "password" were both in the top five. An attacker does not need to be clever, only to try the favourites first.
Most common passwords in breached accounts (2019)
million uses
| Times used | |
|---|---|
| 123456 | 23.2 million uses |
| 123456789 | 7.7 million uses |
| qwerty | 3.8 million uses |
| password | 3.6 million uses |
| 1111111 | 3.1 million uses |
Passwords people think are clever are not much safer. Humans follow patterns, such as a number at the end or a 3 swapped for an E. Those habits are well known, and password-guessing programs come loaded with long lists of common passwords, including real ones from past breaches, plus the usual small modifications of them.
Strength is measured in "bits of entropy", and every extra bit doubles the number of guesses an attacker needs. A study of half a million users put the average human-chosen password at about 40.5 bits. The US and UK security agencies now recommend long, memorable passwords over short, complicated ones, and passphrases of ordinary words like "cassette lava baby" have gained traction as advice.
The other great weakness is reuse. When one site leaks its passwords, attackers try the same pairs on other sites. This is called credential stuffing, and with a hit rate one expert put at up to 2 percent, a million stolen logins can open about 20,000 accounts. That is why security experts recommend a distinct password for every account.
Quiz me
0/3
Recap
A password fails when it is common, patterned, or reused, which is why experts advise long passwords, different for every account.
💡 A trick to remember it · Long beats strange, and one lock per key: a long passphrase for each door, never one key for all.
Surprising fact · "123456" appeared in 23.2 million breached passwords.
Sources (2)
No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.