What are the most common passwords and why can most of them be cracked in just 1 second?

May 3, 2023  18:11

The importance of using strong passwords has been talked about for quite some time, but many people continue to use primitive passwords that would only take a hacker a few seconds to crack. NordPass and its partner researchers have processed more than 3TB of data and identified the 200 most common passwords.

Strangely enough, more than a decade later, passwords like "123456", "guest", "qwerty", "abc123" and others still appear on this list. According to experts, 83% of the passwords on the list can be cracked in less than a second.

In addition to simple combinations of letters and numbers, people create passwords related to the latest sports or fashion events. Many, for example, use variations of the names of American professional sports teams (Detroit Red Wings, Boston Red Sox) as passwords.

Here is a list of the 20 most common passwords in the US:

  1. guest
  2. 123456
  3. password
  4. 12345
  5. a1b2c3
  6. 123456789
  7. Password1
  8. 1234
  9. abc123
  10. 12345678
  11. qwerty
  12. baseball
  13. football
  14. unknown
  15. soccer
  16. jordan23
  17. iloveyou
  18. monkey
  19. shadow
  20. g_czechout

Even if the password protecting your email, banking application, or other important account isn't as primitive as "guest," that doesn't mean it won't be easy to crack. A study by Home Security Heroes showed that artificial intelligence can crack four-six character passwords in just a few seconds. It will take the AI only about seven hours to crack an eight-digit password containing various letters, symbols and numbers, and two weeks for a nine-digit password.

If you want your password to be impossible to guess or crack, it must be at least 12 characters long and contain uppercase and lowercase letters, numbers, and special characters. It would take AI about 30,000 years to crack a password that meets these criteria. And an 18-character password containing numbers, letters, and special characters is generally considered unbreakable: it would take AI six quadrillion years to break it.

To protect accounts, it is also recommended to:

  • Use two-factor authentication 2FA/MFA (preferably not via SMS);
  • Not to use the same password for different accounts;
  • Update passwords regularly, especially for confidential accounts;
  • Avoid using public Wi-Fi, especially for financial transactions;
  • Where possible, physical security keys can also be used for particularly important accounts.

 


 
 
 
 
  • Archive