The hackers who stole and published 33 million passwords from the Rockyou.com website in December needn't have bothered, a security company has revealed. Many of them were so trivial they could have been guessed anyway.
According to a new analysis of the hacked passwords, the most popular password used on the Rockyou site was ‘123456'. Ridiculously, the second most popular password was ‘12345' closely followed (in order) by ‘12345687', ‘Password', ‘iloveyou', ‘princess', and the imaginative ‘rockyou'.
To put the use of ‘123456' into perspective, it was used on 290,731 accounts out of the nearly 33 million, which sounds small until Imperva reveals that the top 20 passwords were all equally transparent, and around 20 percent of the 5,000 most popular passwords were "names, slang words, dictionary words or trivial passwords." In 20th place, 13,856 accounts secured themselves with the word ‘QWERTY'.
Helpfully, Imperva puts this disastrous state of affairs into perspective in its downloadable report that should probably be required reading for companies that do not enforce password complexity.
"If a hacker would have used the list of the top 5,000 passwords as a dictionary for brute force attack on Rockyou. com users, it would take only one attempt (per account) to guess 0.9 percent of the users passwords or a rate of one success per 111 attempts," say its authors.
Read this full article at Tech World
Only registered users can write comments. Please login or register. Powered by AkoComment! |