Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The link posted on the article merits a submission by itself:

"The science of password selection" (a breakdown of common passwords by selection practices, as taken from public leaks)

http://www.troyhunt.com/2011/07/science-of-password-selectio...

In short, passwords are chosen from:

People names: this includes a list of about 26,000 common first and last names.

Place names: this is everything from towns to states to countries and includes about 32,000 entries.

English dictionary

The most common passwords by group:

Name:

   1. maggie
   2. michael
   3. jennifer
Place:

   1. dallas
   2. canada
   3. boston
Dictionary Words:

   1. password (oh dear)
   2. monkey
   3. dragon
Numbers:

   1. 123456
   2. 12345678
   3. 123456789


Is it possible that the breached Sony passwords he was analyzing may have been cracked with dictionary attacks? Maybe the reason only 1% of the passwords had a non-alphanumeric character was that the crackers mostly didn't crack the passwords that had any non-alphanumeric characters.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: