The 25 worst passwords of 2013: 'password' gets dethroned(pcworld.com)
pcworld.com
The 25 worst passwords of 2013: 'password' gets dethroned
http://www.pcworld.com/article/2089244/the-25-worst-passwords-of-2013-password-gets-dethroned.html
12 comments
That's flawed logic. Most of the analysis comes from the Adobe leakage, and arguably a large share of users there didn't care about this service and used an easy and weak password. It would be much more interesting to have stats from active gmail accounts or bank accounts, for instance.
If the users intend to use some site only once but the site forces the users to make passwords, this is unsurprisingly what the passwords will be.
The users are actually quite smart in deciding how much effort is adequate for the realistically expected risk to them. Unless their perception is manipulated.
The users are actually quite smart in deciding how much effort is adequate for the realistically expected risk to them. Unless their perception is manipulated.
That would surely explain why "photoshop" and "adobe123" are so high.
Article is garbage: sample is clearly biased.
Article is garbage: sample is clearly biased.
And even in the GMail case there could be lots of throwaways. Bank accounts usually not, but passwords to those don't leak very often.
Passwords are bullshit and it is our failure as an industry: we should be moving away from passwords.
What alternative is there? When it comes to authentication, there are only a few categories:
1. Something you know: password, secret question, mother's maiden name. These can be forgotten. If the information is generated by the user, it has the potential to be something easily guessed.
2. Something you have: SSH key, GPG key, RSA token, Yubikey, Google Authenticator. These can be quite secure, but hard to use. Losing a physical auth token deprives the user of access. SSH/GPG key pairs depend on the security of the system(s) they're stored on.
3. Something you are: fingerprint, retina scan, face recognition, voiceprint. These are irrevocable and anathema to privacy. Worst of all, they're not very reliable or secure. Fingerprint scanners are stymied if one has recently been lifting weights or rock climbing. Face recognition is affected by lighting, makeup, glasses, hair, sunburn/tan, age, etc. Voice auth is a joke. It can fail due to emotional stress, sickness, or background noise.
Combinations can be used for more secure authentication, but so far nothing has been as simple or as convenient as a password.
1. Something you know: password, secret question, mother's maiden name. These can be forgotten. If the information is generated by the user, it has the potential to be something easily guessed.
2. Something you have: SSH key, GPG key, RSA token, Yubikey, Google Authenticator. These can be quite secure, but hard to use. Losing a physical auth token deprives the user of access. SSH/GPG key pairs depend on the security of the system(s) they're stored on.
3. Something you are: fingerprint, retina scan, face recognition, voiceprint. These are irrevocable and anathema to privacy. Worst of all, they're not very reliable or secure. Fingerprint scanners are stymied if one has recently been lifting weights or rock climbing. Face recognition is affected by lighting, makeup, glasses, hair, sunburn/tan, age, etc. Voice auth is a joke. It can fail due to emotional stress, sickness, or background noise.
Combinations can be used for more secure authentication, but so far nothing has been as simple or as convenient as a password.
You can split 2. into several pieces which will allow you to recover if you lose something. Imagine you have a SSH key, an authenticator token and a printed physical QR code and you can restore either of that if you have both of the rest.
and use what authenticators?
We should figure it out. Some cryptography obviously, safe but recoverable.
Microsoft, Google, and others seem to be behind FIDO[1].
[1] http://en.wikipedia.org/wiki/FIDO_Alliance
[1] http://en.wikipedia.org/wiki/FIDO_Alliance
> 4. qwerty
> 23. azerty
Thank you france.
> 23. azerty
Thank you france.