Building the Ideal 100-word Password List
[Via danielmiessler.com]
There’s some phenomenal password research here from clarkson.edu that talks about common passwords found during Internet attacks.
I’ve taken those entries and put them into a single list here on Github, and I will soon be adding the abridged rockyou list (once I get their permission). Thanks to @jhaddix for pointing me toward that list.
[More]
Reading the paper is pretty revealing. Hackers use what works so looking at what they try gives an idea of what provides them with success.
If they figure out a username, they often use passwords based on that.Many times they will use a password that is the same as the username.
They use a series of attack dictionaries to help. And some of the passwords that were used are actually ones rated ‘strong’ by password checkers.
All and all, a good primer on passwords to stay away from.


February 12, 2012 at 1:24 pm
If I click on this link and look at the passwords, how can I be sure that my password won’t be stolen?