Featured Stories

Stop Using '123456': The 50 Worst Passwords Exposed by the Gawker Hack

Stop Using '123456': The 50 Worst Passwords Exposed by the Gawker Hack

In December 2010, hackers broke into Gawker Media's servers and walked off with the usernames and passwords of well over a million commenters across sites like Gizmodo and Lifehacker. Then they published the lot.

Security researchers did what researchers do: they analyzed the stolen passwords. The results were equal parts predictable and depressing. The most common choices were things like "123456," "password," "qwerty," and "abc123" — Sophos published a widely cited analysis of the top 50 at the time. These weren't clever people making one mistake. They were millions of people making the same mistake.

But the passwords themselves were never the worst of it. The breach laid bare the habit that actually gets people robbed: reuse. A huge share of users had the same password on every site — email, shopping, social media, all of it. Steal one database and you hold the keys to everything. Gawker's attackers didn't need to be brilliant. They just needed one weak link and everyone else's convenience.

Attackers have always known this. Worms like Conficker shipped with built-in lists of the most common passwords and simply tried them one by one. It worked, at scale. A dictionary attack doesn't guess — it recites.

The fix was obvious then and is obvious now, and most people still don't do it: never reuse a password across sites, never pick a dictionary word, and let a password manager carry the memory load. A site can do its part too, by rejecting weak passwords at signup instead of lecturing users after a breach.

The Gawker list was a mirror. Fifteen years later, most of us are still in it.

passwordssecurity

Related Stories