Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 13 submissions in the queue.
posted by martyb on Sunday December 06 2020, @05:22AM   Printer-friendly
from the it's-just-the-letter-A dept.

After analyzing 15 billion passwords, these are the most common phrases people use:

[...] the CyberNews Investigation team was interested in what kind of patterns everyday people were using in creating their own passwords. We collected data from publicly leaked data breaches, including the Breach Compilation, Collection #1-5, and other databases. We then anonymized the data and detached the passwords so that we could look at that data in isolation.

In total, we were able to analyze 15,212,645,925 passwords, of which 2,217,015,490 were unique. We discovered some interesting things about the way that people create passwords: their favorite sports teams, cities, food and even curse words. We could even deduce the probable age of the person by looking at which year they use in their password.

As the data came in various forms, we filtered the results to only include terms that we could make sense of, and from which we could gather some insights.

[...] Of course, at this point this conversation has all become moot: the best passwords are the ones that you don't need to remember at all. For this reason, we normally strongly recommend that people use password managers. These easy-to-use tools will create very complex passwords for you that you don't even have to remember.

They mostly come as browser extensions that will create or fill in your usernames and passwords for you. The only thing you need to remember is one master password to use the password managers.

Now, if you noticed that your own personal passwords have similar patterns to the ones we analyzed, and that these passwords can be considered rather simple, we recommend you visit our Data Leak Checker to see if your email address and other personal data has been exposed in a data breach.

The CyberNews Data Leak Checker currently has the largest database of known breached accounts, with more than 15 billion compromised accounts. So, chances are that if your account has been leaked, we'll probably have a record of it.

(Emphasis from original retained here.)

Another useful site for checking if an email address has been compromised is: https://haveibeenpwned.com/.


Original Submission

Related Stories

Why Passwords Still Rock 13 comments

A lot of security myths have acquired lives of their own and taken as facts. Dr. Andy Farnell over at the Cyber Show's blog has posted an item about where passwords can still fit in as a part of general authentication despite what fleets of salesmen selling authentication gimmicks tell us.

Security models: password or tracker?

Indeed people do not discriminate two vastly different security models that should really be obvious with a moments thought. The question is, "who is the security for?"

Security schemes that ask that you carry around a device which is connected permanently to a network and uses a mechanism that is entirely opaque to you is a different kind of security. It is more than a mere access control. It is not security for you.

It may pass for "something you have" but also has a function to act as a location or close proximity biometric remote sensor for an observer elsewhere. It's a tracking device.

[...] Partly it's because we've been using passwords wrong for about the past 40 years. The new NIST document partially puts that right. It's also because there's a massive "security industry" that sells things - and you can't sell people the ability to think up a new password in their own head. Where's the profit in that?

Instead they'll tell you that you need a fangled security system of gadgets and retina scans, and that you're too stupid to be trusted with your own security. They are wrong. In most cases passwords are just fine if not better than alternatives, and in this post we're going to explain why.

Thus another theme of this essay is personal responsibility and the crux of the argument is that all security solutions which are not passwords solve problems that are not yours.

Like self-service checkouts at the supermarket that make customers into employees, they are a way of passing blame, liability, and work onto you in order to solve someone elses security problem. As Prof. Ross Anderson bluntly puts it;

"If Alice guards a system but Bob pays the cost of failure, you can expect trouble."

Cybersecurity has become more harmful than helpful in many cases and biometrics are more of a user name than a password despite the constant misuse as the latter.

Previously:
(2024) NIST Proposes Barring Some of the Most Nonsensical Password Rules
(2024) VISA and Biometric Authentication
(2023) A Fifth of Passwords Used by Federal Agency Cracked in Security Audit
(2020) Here's Yet Another Reason Why You Really Should Start Using Better Passwords


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 5, Insightful) by DrkShadow on Sunday December 06 2020, @05:29AM (11 children)

    by DrkShadow (1404) on Sunday December 06 2020, @05:29AM (#1084496)

    Still missing the point that just because we're forced to create an account for something we'll never do again (post, once, on a forum) that the password there needs to be th3 most SECURR!!! EVAR!

    Still missing the point. We don't care about any of those accounts. I have created an account on a forum for which my password was literally one character. (You'll never guess it. Not in 30 picoseconds.)

    Still missing the point. These articles keep getting posted to this site where everyone constantly replies that the articles are based in fallacy.

    • (Score: 0) by Anonymous Coward on Sunday December 06 2020, @08:39AM

      by Anonymous Coward on Sunday December 06 2020, @08:39AM (#1084510)
    • (Score: 5, Interesting) by darkfeline on Sunday December 06 2020, @12:18PM (8 children)

      by darkfeline (1030) on Sunday December 06 2020, @12:18PM (#1084523) Homepage

      You never know when some innocuous activity or piece of data on some site might screw you over later. No one gets screwed by a vulnerability that they anticipated. It's always the ones you don't anticipate that screw you. Why take the chance when generating a random password and filling it in is free? It literally takes more effort to make up a weak throwaway password for a website and bypass your password manager.

      --
      Join the SDF Public Access UNIX System today!
      • (Score: 4, Informative) by epitaxial on Sunday December 06 2020, @05:29PM (2 children)

        by epitaxial (3165) on Sunday December 06 2020, @05:29PM (#1084596)

        When I register for those bullshit forums or websites I use a throw away email account. Compromise them all you want. Also fuck manufacturers who make you register to view datasheets.

        • (Score: 0) by Anonymous Coward on Monday December 07 2020, @02:01AM (1 child)

          by Anonymous Coward on Monday December 07 2020, @02:01AM (#1084735)

          Can you get datasheets via digikey instead?

          • (Score: 2) by epitaxial on Monday December 07 2020, @06:12PM

            by epitaxial (3165) on Monday December 07 2020, @06:12PM (#1084962)

            Sometimes they just link to the manufacturer who makes you register.

      • (Score: 4, Insightful) by Grishnakh on Sunday December 06 2020, @05:51PM (4 children)

        by Grishnakh (2831) on Sunday December 06 2020, @05:51PM (#1084600)

        What password manager? That's a pretty bad assumption, that I use one of those.

        Many times when I'm forced to create an account for something, I'm on my work computer. There's no password manager there. And if there were, and then I wanted to access that account from my computer at home, how exactly am I supposed to synchronize the password managers? (answer: you can't)

        Password managers only make sense if you're always accessing that site from the same computer, or from computers you control (i.e., some password managers let you sync between your home PC and your phone). Throw a work computer (or a friend's computer) in there and it all goes out the window.

        • (Score: 2) by darkfeline on Sunday December 06 2020, @11:12PM (1 child)

          by darkfeline (1030) on Sunday December 06 2020, @11:12PM (#1084694) Homepage

          > I'm on my work computer

          If you're accessing resources on behalf of a company, it's the company's responsibility to set and enforce good security policies. I won't comment specifically on your company's policies, but if they don't provide password management they should probably fix their shit.

          >you're always accessing that site from the same computer, or from computers you control (i.e., some password managers let you sync between your home PC and your phone). Throw a work computer (or a friend's computer) in there and it all goes out the window.

          If you're accessing resources from untrusted computers, you should consider yourself compromised. Your friend (and anyone who has compromised your friend) has full access to everything you've done on their computer.

          --
          Join the SDF Public Access UNIX System today!
          • (Score: 2) by Grishnakh on Monday December 07 2020, @03:10PM

            by Grishnakh (2831) on Monday December 07 2020, @03:10PM (#1084902)

            If you're accessing resources from untrusted computers, you should consider yourself compromised. Your friend (and anyone who has compromised your friend) has full access to everything you've done on their computer.

            Right, and why exactly should I care about this?

            This is the problem with all this security crap: why should I care so much about other people seeing things I've done, or gaining access to my accounts?

            Sure, if we're talking about my bank accounts or anything else important like that (esp. anything that involves money), then definitely I want security.

            But why should I care about having so much security to keep people out of my SoylentNews account? Or some other random internet forum or comment board, where I don't even use my real name, only a pseudonym?

            The problem is that every stupid site out there wants you to not only have an "account", as if they're all SO important, but they also have ridiculous password requirements so I can't just have a simple one-word password that I share across them.

            Seriously, I don't give two shits if some determined hacker breaks into my soylentnews account. It's easy enough to create another one.

            (And if it isn't obvious, I wouldn't use some other person's computer for sensitive stuff like my banking.)

        • (Score: 0) by Anonymous Coward on Monday December 07 2020, @04:40AM (1 child)

          by Anonymous Coward on Monday December 07 2020, @04:40AM (#1084780)

          What password manager? That's a pretty bad assumption, that I use one of those.

          Then perhaps you should refrain from talking out your ass about something you don't seem to know anything about.

          how exactly am I supposed to synchronize the password managers? (answer: you can't)

          Huh? What the hell are you talking about? There are all sorts of ways of synchronizing password manager files across computers, just like any other files. Some people set up automatic sync via any sort of secure syncing software. Some do periodic manual transfers. Some -- particularly those who use the browser plugin password managers (a recipe for disaster if you ask me, but they seem popular) -- have built-in integrated syncing services, often for a fee. For those who are more paranoid, their password file lives on a USB key they carry with them everywhere and can just be plugged into whatever computer you're using at the moment.

          If you're talking about the fact that your home and work password managers may be different or use different sets of passwords -- fine, set up multiple password files. Use multiple password manager apps if necessary, and just add the passwords you need in more that one location to all of them.

          I have no idea what "answer: you can't" is supposed to mean. It's not an intractable problem -- people do it all the time. And if your problem is that your work computer is so closed down that you can't install a proper password manager on it, well, I wonder what the hell you're trying to access personal websites, etc. on it for then, because that sort of system probably is locked down enough that they don't want you to be doing that.

          Password managers only make sense if you're always accessing that site from the same computer, or from computers you control (i.e., some password managers let you sync between your home PC and your phone).

          Oh, so you realize that syncing exists? Yes, you can also sync across multiple computers. Amazing things one can do these days! And if it's not built-in functionality for the app, you can either set up an automatic or manual sync, or do the USB drive solution I mentioned above. Easy peasy.

          Throw a work computer (or a friend's computer) in there and it all goes out the window.

          I have been using password managers of various types for 15 years now, and I can literally count on one hand the times that I've been unable to log into a site when needed to on some other system. Generally, as you note, I can have the password file on my phone too. And half of those 4-5 times over the past 15 years that I had a problem, it was because I hadn't even bothered to install the password manager on a new phone yet... or a phone I had for over a year... because it's literally NEVER that I need access to these passwords on other devices.

          Seriously -- why would I need a password manager and file on a friend's computer? Under what circumstances? The few logins I actually may need to access on other computers on rare occasions -- well, I set those up with a password I can actually remember and put in two-factor authentication. That's literally a number of passwords again that I can count on one hand. The rest? Well, I'm not going to access more stuff I really care about (like bank or other financial data) on someone else's system. And why the fuck would I need to access some stupid random password to some internet forum or something on a friend's computer? Again, there are literally like 4-5 passwords I might on occasion need to log in from somewhere else (like frequently used email accounts), so there I actually know the password.

          Why not use a password manager for every other use case? You can debate various security issues if you want about them (and some are more or less secure than others), but your objections are just weird. Why people have upvoted your post, I have no idea.

          • (Score: 2) by Grishnakh on Monday December 07 2020, @03:18PM

            by Grishnakh (2831) on Monday December 07 2020, @03:18PM (#1084907)

            You keep glossing over the work computer bit. I don't have access on my work computer to install random browser extensions; most workplaces are like this because of the dangers of browser extensions. And the stuff I do on my work computer is with sites where I don't care about having high security (i.e., not banking), it's stupid stuff like *this* site, when I'm on my lunch break. As for "that they don't want you to be doing that", they don't care if I read soylentnews on my lunch break. Seriously? This is the problem with this password manager bullshit: I cannot sync it across my own computer and computers I don't own or control (namely my work computer), yet the stuff I do on the work computer is precisely the stuff where I really *don't care* about security very much, yet I'm forced to make up different passwords for every stupid little site I browse in my spare time.

            And NO, I am NOT going to fuck around with manually copying passwords between these systems for randomstupidinternetforum.com.

    • (Score: 0) by Anonymous Coward on Sunday December 06 2020, @04:34PM

      by Anonymous Coward on Sunday December 06 2020, @04:34PM (#1084580)

      is the fallacy fallacy a fallacy?

  • (Score: 0) by Anonymous Coward on Sunday December 06 2020, @06:11AM (5 children)

    by Anonymous Coward on Sunday December 06 2020, @06:11AM (#1084501)

    I remember a number of those things compromised in recent years. Their users basically gave their e-lives away on a disk platter, and what for?

    If someone can steal a site's password DB, it means the place is run by idiots and insecure whatever your password is.

    If someone can brute-force a password on a site, it means the same thing.

    In either case, you lose what you had on that one single site.

    • (Score: 1, Informative) by Anonymous Coward on Sunday December 06 2020, @08:01AM (4 children)

      by Anonymous Coward on Sunday December 06 2020, @08:01AM (#1084507)

      Yes, the advantage of a password manager is you can use a different password for each site. When one site is breached, they haven't captured your passwords for any other site.

      Of course if you keep all your passwords in the password manager's cloud (however that's implemented), if the manager's site is breached, you lose everything.

      If you keep your password manager's files local on your computer, and if your computer is breached... well, you're fucked anyway at that point.

      If you keep your password manager's files local and encrypted with a completely different encryption scheme, and the government wants you, they'll come in, seize your computer while you're dragged off to jail, they'll put child porn on your computer before handing it over to the tech guys for them to "find" the CP, and then you'll either tell them what they want or do what they want, or you'll get raped to death by prison gangs.

      The only way to really keep a secret is to erase all records of it, kill anyone who ever knew it, and then blow your own brains out. Nuking from orbit is an additional layer of security.

      • (Score: 5, Interesting) by Anonymous Coward on Sunday December 06 2020, @08:24AM (3 children)

        by Anonymous Coward on Sunday December 06 2020, @08:24AM (#1084509)

        Or, you know, you could do something simple like I do...

        Write logins and passwords on a sheet of paper with a pen or pencil, yes, I know, horrors and all that, but they are quite reliable. When the paper starts to fill up (every few years) I re-copy, get rid of dead entries. For backup, I photocopy the page and leave the copy at my folks house (nearby)--another option would be to leave the copy in my small firesafe box along with passport, etc.

        Medieval scribes were reasonably successful in keeping civilization alive.

        • (Score: 3, Interesting) by legont on Sunday December 06 2020, @01:01PM (1 child)

          by legont (4179) on Sunday December 06 2020, @01:01PM (#1084530)

          It's a good strategy. It also could be improved by writing not actual passwords, but hints. This would give you enough time to change them if you lose the paper. One could also manually encrypt the list using a trivial cypher. If the password is a random string already, cracking would take a considerable time even for a trivial letter substitution one.

          --
          "Wealth is the relentless enemy of understanding" - John Kenneth Galbraith.
          • (Score: 0) by Anonymous Coward on Sunday December 06 2020, @04:02PM

            by Anonymous Coward on Sunday December 06 2020, @04:02PM (#1084563)

            There is another hole I forgot to mention. With original photocopy (optical process) the copy was quite unique/secure. But now "photocopiers" are all scan-->print devices, so there is a chance that the bitmap could be pirated by some clever bad actor. There is defense in depth...my handwriting is poor and inconsistent!

        • (Score: 0) by Anonymous Coward on Sunday December 06 2020, @04:58PM

          by Anonymous Coward on Sunday December 06 2020, @04:58PM (#1084587)

          Write logins and passwords on a sheet of paper with a pen or pencil, .... For backup, I photocopy the page and leave the copy at my folks house

          Well, here is a suggestion for you: Take a photo will your cell-phone instead, this way the page will not be send to the manufacturer and a slice of a tree is saved. As a bonus, you can always look up your passwords on Google photos in case you loose your sheet or your phone.

  • (Score: 5, Touché) by deimios on Sunday December 06 2020, @06:25AM (9 children)

    by deimios (201) on Sunday December 06 2020, @06:25AM (#1084502) Journal

    Brilliant, so now you don't need to compromise passwords on a site-by-site basis, you just attack the password manager main password and get ALL the passwords.

    Good thing they aren't so easy to exploit. Or are they... https://www.forbes.com/sites/daveywinder/2019/09/16/google-warns-lastpass-users-were-exposed-to-last-password-credential-leak/ [forbes.com]

    • (Score: 4, Informative) by RS3 on Sunday December 06 2020, @12:00PM

      by RS3 (6367) on Sunday December 06 2020, @12:00PM (#1084521)

      That and sometimes the password managers themselves are the leaker.

      https://www.tomsguide.com/news/password-manager-hacks [tomsguide.com]

    • (Score: 5, Interesting) by legont on Sunday December 06 2020, @12:49PM (5 children)

      by legont (4179) on Sunday December 06 2020, @12:49PM (#1084528)

      That's why I use a password manager that I wrote myself. While I am sure it can be hacked, I doubt it makes sense to do just to get me alone. (no, it does not store passwords)
      What pisses me off is that some idiots out there prohibit paste into the password field. They force users to actually manually type their passwords - a paradise for key loggers and password guessing.

      --
      "Wealth is the relentless enemy of understanding" - John Kenneth Galbraith.
      • (Score: 1, Interesting) by Anonymous Coward on Sunday December 06 2020, @03:27PM (1 child)

        by Anonymous Coward on Sunday December 06 2020, @03:27PM (#1084557)

        What pisses me off is that some idiots out there prohibit paste into the password field. They force users to actually manually type their passwords - a paradise for key loggers and password guessing.

        If you can keylog, then you can just grab the paste, no?

        • (Score: 1, Insightful) by Anonymous Coward on Sunday December 06 2020, @08:29PM

          by Anonymous Coward on Sunday December 06 2020, @08:29PM (#1084651)

          If the computer system you are using contains a keylogger, then you the user have already lost the battle of keeping anything private.

          Clean out the keylogger (unless the keylogger is on a $work machine, in which case, only use $work machine for $work) and start over again once it is gone.

      • (Score: 3, Interesting) by Anonymous Coward on Sunday December 06 2020, @05:11PM (2 children)

        by Anonymous Coward on Sunday December 06 2020, @05:11PM (#1084591)
        1. Run Firefox
        2. Open Firefox about:config panel
        3. Find about:config item dom.event.clipboardevents.enabled
        4. Set dom.event.clipboardevents.enabled item to false

        Bam - websites can no longer block pasting into password fields.

        • (Score: 0) by Anonymous Coward on Monday December 07 2020, @12:13AM (1 child)

          by Anonymous Coward on Monday December 07 2020, @12:13AM (#1084707)

          > Run Firefox
                  Open Firefox about:config panel
                  Find about:config item dom.event.clipboardevents.enabled
                  Set dom.event.clipboardevents.enabled item to false

          Cool, thanks.
          Now, tell me how you put numbers in your list that FF wouldn't let me hilight (thus when I copied your list I only got the text, not the numbers).

          • (Score: 1, Informative) by Anonymous Coward on Monday December 07 2020, @12:21AM

            by Anonymous Coward on Monday December 07 2020, @12:21AM (#1084709)
            The list is just a standard HTML <ol> list with standard <li> elements.

            The numbers get added by the browser on display, so apparently the browser is also not copy/pasting out those numbers that it added.

    • (Score: 2) by JoeMerchant on Sunday December 06 2020, @01:55PM

      by JoeMerchant (3937) on Sunday December 06 2020, @01:55PM (#1084540) Journal

      just attack the password manager main password and get ALL the passwords.

      One Ring to rule them all, One Ring to find them,
      One Ring to bring them all, and in the darkness bind them.

      --
      🌻🌻🌻🌻✌️ [google.com]
    • (Score: 2) by Mojibake Tengu on Sunday December 06 2020, @04:49PM

      by Mojibake Tengu (8598) on Sunday December 06 2020, @04:49PM (#1084584) Journal

      No need to hack a password manager directly, subverting its UI for passive harvest is often sufficient enough.

      One of the best candidates for such trick is Qt.

      --
      The kinder you are, the easier it is for wicked people to morally coerce you.
  • (Score: 2) by Rosco P. Coltrane on Sunday December 06 2020, @04:03PM (3 children)

    by Rosco P. Coltrane (4757) on Sunday December 06 2020, @04:03PM (#1084565)

    the best passwords are the ones that you don't need to remember at all. For this reason, we normally strongly recommend that people use password managers.

    What a crock of shit: keep your passwords all in one place means whoever attacks that one place successfully gets the keys to all your casles. And don't get me started on cloud-based password managers: that's so stupid from a security standpoint it beggars belief.

    The best passwords are in you're brain, and they're the ones based on a recipe, not a dump series of characters you have to remember.

    My recipe is this: the basis is a long line of poetry from a French poet I like. I take every first letter of each word of that line. Then I prefix the beginning with the first letter of the website, hostname of username it concerns, suffix it with the last two digits of the year I created / opened the account (which I either remember or write down somewhere for places I seldom visit) then suffix it with the 2nd and 3rd digit of the website / hostname / username.

    Basically all I have to remember is the line of poetry, and 2 digits if I want to login faster.

    • (Score: 1) by shrewdsheep on Sunday December 06 2020, @05:03PM (1 child)

      by shrewdsheep (5215) on Sunday December 06 2020, @05:03PM (#1084589) Journal

      Well, here is a compromise. Use a password manager for your throw-away stuff and remember the important passwords in your b-RAM, eh... brain.

      • (Score: 0) by Anonymous Coward on Sunday December 06 2020, @09:53PM

        by Anonymous Coward on Sunday December 06 2020, @09:53PM (#1084675)

        For instance, your first laptop password might be "Hunter00" your second would be "Hunter01" then your third... um, let me guess "Hunter02"

        The next one will probably be "BigGuy"

    • (Score: 1, Informative) by Anonymous Coward on Monday December 07 2020, @04:57AM

      by Anonymous Coward on Monday December 07 2020, @04:57AM (#1084785)

      So, let's assume you didn't actually tell us your REAL method (as that you be profoundly stupid to post on a public website), but something somewhat similar to what you do.

      In that case, you have one person who manages to get TWO of your passwords, and then can likely figure out your system and then you're fucked. No? You think you're the first genius to use some aspects of the URL in creating custom passwords for sites?

      I agree with you that cloud-based password managers are idiocy. But ones that are based on a file that only resides on your home computer and is encrypted securely? Listen -- if someone can access your system enough to install a keylogger or something and be able to get your master password AND steal your password file or remotely probe it once they have your master password, you're fucked no matter what your password system is. That sort of person could be stealing every password you're using on your computer right now.

      Best solution: use a password manager for random throwaway passwords on various sites to avoid patterns. Use the password manager for sites you really want to keep secure too, but turn on two-factor authentication for those sites as well. If you're really paranoid about a few particular logons or accounts, then memorize those with a long passphrase that is unlike any other password you use. Or, for ones that you're slightly less paranoid about, put them in a separate encrypted password file in your manager, so even if they get access to your junk master password file, they still can't get access to everything.

      I'm not saying your system is bad. But it's best to avoid obvious similarities or patterns between passwords for anything you want to keep actually secure. In the grand scheme, someone's unlikely to figure out your system unless they're a really dedicated hacker who wants something specific from you. But if they're the sort of person who can get access to your physical system enough to hack into a password manager that only resides on your computer, you're pretty fucked no matter what.

(1)