Social networking site breach exposes most popularly used passwords

An analysis of more than 32 million exposed passwords revealed "123456" as the most commonly used security code when logging into online accounts.

Social networking services and customized widget company, Rockyou.com, suffered a data breach in December 2009.

The breach included millions of people's email addresses and passwords for Rockyou.com (and in many cases passwords and login details for associated social networking sites). The hacker responsible for the attack subsequently posted the full list of passwords on the internet.

The compromised password and login data was examined by US-based security company, Imperva Application Defense Center (ADC).

The ease and scale of this security breach should read as a warning to everyone logging onto web-based social networks, email accounts or online ecommerce sites - especially those who use the same passwords for multiple accounts.

Pairing short, uncomplicated and easy-to-guess passwords with identical login credentials for multiple sites can put you at serious risk of identity theft and can easily result in your accounts being compromised by prying eyes.

"Everyone needs to understand what the combination of poor passwords means in today's world of automated cyber attacks: with only minimal effort, a hacker can gain access to one new account every second-or 1000 accounts every 17 minutes," explained Imperva's CTO Amichai Shulman in a January 21 report announcement.

"The data provides a unique glimpse into the way that users select passwords and an opportunity to evaluate the true strength of passwords as a security mechanism. Never before has there been such a high volume of real-world passwords to examine."

Surprisingly, the analysis of the Rockyou.com data confirms that consumer password habits have changed very little over the past two decades. Almost 50 percent of users opt for passwords that are names and easily understood words or use trivial passwords such as consecutive digits and adjacent keyboard keys.

A full analysis of the 32 million Rockyou.com passwords show the most commonly used passwords are:
1. 123456
2. 12345
3. 123456789
4. Password
5. iloveyou
6. princess
7. rockyou
8. 1234567
9. 12345678
10. abc123

To keep your accounts safe, NASA recommends adhering to the following steps when creating a password:

1. It should contain at least eight characters.
2. It should contain a mix of four different types of characters - upper case letters, lower case letters, numbers, and special characters such as !@#$%^&*,;" If there is only one letter or special character, it should not be either the first or last character in the password.
3. It should not be a name, a slang word, or any word in the dictionary. It should not include any part of your name or your e-mail address.
4. Choose a strong password for sites where you care about the privacy of the information you store. Bruce Schneier's advice is useful: "take a sentence and turn it into a password. Something like "This little piggy went to market" might become "tlpWENT2m." That nine-character password won't be in anyone's dictionary."
5. Use a different password for all sites - even for the ones where privacy isn't an issue. To help remember the passwords, again, following Bruce Schneier's advice is recommended: "If you can't remember your passwords, write them down and put the paper in your wallet. But just write the sentence - or better yet - a hint that
will help you remember your sentence."
6. Never trust a third party with your important passwords (webmail, banking, medical etc.)

The information formed part of Imperva's Consumer Password Worst Practices report.

Independent Comment
blog comments powered by Disqus
Top stories
News in pictures
World news in pictures
UK news in pictures
UK news in pictures
More stories
       
Independent
Travel Shop
Imperial Cities of Morocco
Seven nights half-board from only £799pp Find out more
Historic Sicily
Seven nights half-board from £799pp Find out more
4* all-inclusive Crete
Seven nights from only £399pp Find out more

Day In a Page

Andrew Mitchell: 'It's no good feeling hard done by'

Andrew Mitchell: 'It's no good feeling hard done by'

In his first interview since 'plebgate', the former Chief Whip opens up just enough to concede that, in politics, you have to take the rough with the smooth
Corruption and the FCO: Blue skies, white sands, dark clouds

Corruption and the FCO: Blue skies, white sands, dark clouds

Special report: Met police call for criminal inquiry into former diplomat's Cayman Islands rule
Fallen angel: Winona Ryder on bouncing back from her decade in the wilderness

Fallen angel: Winona Ryder bounces back

She owned the 1990s... but then she disappeared. Now, Ms Ryder is back with quite the bang in her latest role, as the wife of a notorious real-life Mob hitman.
Roman Polanski shakes Cannes Film Festival

Roman Polanski shakes Cannes Film Festival

The director's new film, 'Venus in Fur', is one of the raciest on offer
Rev Richard Coles: 'I don’t have any concerns that God is cross with me for being gay and eventually the Church won’t either'

Rev Richard Coles on the Church and homosexuality

The mellifluous, erudite and witty Coles is the nation's most pop-culture-friendly priest
'Baghdad likes to live from crisis to crisis': Civil war looms in Iraq

Patrick Cockburn: Civil war looms in Iraq

The governor of Kirkuk - one of the country's most violent but successful provinces - fears the worst
Written on the body: Tattooists at pains to point out their artistic credentials

Written on the body

Tattooists at pains to point out their artistic credentials
Conquering Everest: 60 facts about the world's tallest mountain

Conquering Everest: 60 facts about the world's tallest mountain

The IoS marks the sixtieth anniversary of Sir Edmund Hillary and Tenzing Norgay first reaching the peak of the highest mountain on Earth
A new, and irreversible, Dust Bowl looms

Rupert Cornwell: A new, and irreversible, Dust Bowl looms

The destructive power of tornadoes will be as nothing once the Great Plains' vast underground water reserve dries up
Every creature's needless death diminshes us all

Philip Hoare: Every creature's needless death diminishes us all

A 60 per cent decline in our national species should alarm us, yet few of us act. But to mind more about animals would reflect well on society
Killing with kindness: Burma's religious battleground - and the monks at the heart of it

Killing with kindness: Burma's religious battleground

Six years ago, the world cheered the monks behind Burma’s Saffron Revolution. Now, a horrific new eruption of religious slaughter is being blamed on a 'Buddhist Bin Laden'.
Let's take it outside: Bill Granger's Bank Holiday feast

Let's take it outside: Bill Granger's Bank Holiday feast

You can’t always depend on the weather – but you can avoid the pitfalls of the British barbecue by preparing an elaborate outdoor feast indoors ahead of time...
The Calvin report: Stirring Champions League final shows how far English game must advance

The Calvin report

Stirring Champions League final shows how far English game must advance
10 big questions for the British & Irish Lions to answer

10 big questions for the British & Irish Lions to answer

Warren Gatland's squad fly Down Under aiming to do justice to the expectations – and hoping the Wallabies stay in the pub
The Last Word: Golf must end the hypocrisy before its halo slips totally

The Last Word

Golf must end the hypocrisy before its halo slips totally