Passwords That Won’t Keep You Safe

These Passwords Won't Keep You Safe OnlineI could not let 2021 wrap up without the annual look at the OMG WTF are they thinking worst passwords list. I have been covering the sorry-state of passwords since 2010 and unfortunately little has changed. The biggest change has come in the increased number of mega-breaches leaking passwords all over the Intertubes.

Nordpass logoHere is NordPass’s 2021 list. Nordpass and independent cybersecurity researchers evaluated a database with 4 terabytes’ worth of data. You can visit the NordPass website to see all 200 of the entries from 2021. But here are the top 25 most common passwords:

2021's Worst Passwords

2021's 25 worst passwords compiled by Nordpass.
RankPasswordChange from 2020
1123456-
2123456789-
312345+5
4qwerty+8
5password(1)
612345678-+1
7111111(2)
8123123(2)
91234567890(1)
101234567+1
11qwerty123New
12000000+3
131q2w3eNew
14aa12345678New
15abc123(2)
16password1+3
171234(1)
18qwertyuiop+6
19123321+4
20password123New
211q2w3e4r5tNew
22iloveyou(5)
23654321+1
24666666New
25987654321New

Bad password factoids

  • The top 25 bad passwords can be cracked in less than 1 second by a bot (or person) according to Nordpass.
  • different types of passwords94% of the most frequent passwords – can be cracked in less than 10 seconds
  • The most secure password “myspace1” ranked #54 on the list. It was used by 1,619,027 users and can be cracked in 3 hours.
  • The most popular sport on the list is “football.” It ranked #60 and was used by 1,468,381 users.
  • Superman” protected 1,180,436 accounts. He ranked 81st but could be cracked in less than 1 second.
  • The most popular movie on the list was “starwars.” 701,474 users tried to use the Force to protect their accounts. Unfortunately the Force is not strong with this one, it could be cracked in less than 1 second.

Password risk index

The NordPass researchers also devised a risk index based on the number of passwords leaked in each country per capitaRussia came in first with an astounding 19.9 passwords leaked per capita. Other counties that leaked the most passwords are:

  • The Czech Republic 6.2,
  • France 6.0,
  • Germany 5.8,
  • U.S. 5.2,
  • Italy 4.4,
  • Canada 3.6,
  • Australia3.3
  • and Poland 3.6.

rb-

You can test the strength of your password by visiting this site and typing it in. They claim the site isn’t creating a repository of passwords because your information is never sent over an internet connection. The best part? As you type, the software tells you approximately how long it would take a computer to figure out your password. The site turns red if your password is weak but slowly turns green as you make it stronger. It’ll even give you tips on how to improve your password security.

 

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Comments are closed.