Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

123456: The worst passwords of 2011

If one of your passwords is "654321" or "superman" or "qazwsx" congratulations for having one of the least secure passwords of 2011.

Internet users never learn. No matter how many times we hear about obvious, hackable passwords, people keep using them. And the situation doesn't seem to be getting better.

Below is a list of the 25 worst passwords of 2011, compiled by SplashData. The security software developer generated the list from millions of actual stolen passwords, posted online by hackers. Not surprisingly, the most common passwords are also the worst, including "password," "123456" and "qwerty." Even passwords that seem kind of unique, like "trustno1" and "shadow" are actually quite common. And why does "monkey" always show up on these lists?

Anyway, here's the full list:

1. password

2. 123456

3. 12345678

4. qwerty

5. abc123

6. monkey

7. 1234567

8. letmein

9. trustno1

10. dragon

11. baseball

12. 111111

13. iloveyou

14. master

15. sunshine

16. ashley

17. bailey

18. passw0rd

19. shadow

20. 123123

21. 654321

22. superman

23. qazwsx

24. michael

25. football

SplashData has a few recommendations for keeping your data safe:

First, create a strong password consisting of letters, numbers and symbols. If you're worried about remembering long passwords, try using phrases of short words separated by underscores, such as "shiny_phones_rule_1." A phrase is easier to recall than a long, abstract mish-mash of characters.

Second, try not to spread the same password all over the Internet. At the very least, use separate passwords for important uses like online banking and e-mail. The last thing you want is for some poorly protected web forum to hold the same password as your bank account.

To make things super-simple, you can also use password management software, such as LastPass, Roboform, eWallet, SplashID or the free KeePass. These programs remember your passwords, allowing you to create long, complex strings of letters and numbers that you otherwise wouldn't be able to remember.

Also, see PCWorld's guide to creating better passwords, and advice on protecting your passwords. If you follow any of these tips, you're in better shape than the person who uses "abc123."

Follow Jared on Facebook, Twitter or Google+ for even more tech news and commentary.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: BlackBerry, Facebook, Google, Newman
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: security, SplashData
Latest Blog Posts
Whitepapers
  • Award-winning unified information security from Clearswift.
    Fully integrated web and email gateway security solution, providing - protection from inbound threats, policy based encryption, and data loss prevention.
    Learn more »
  • Selecting an Application Lifecycle Management Vendor: An Ovum Report
    Leading industry analyst firms across the world include IBM Rational in their research efforts and provide opinions on our ALM solutions. Find out how Ovum confirmed IBM Rational as the clear leader on both axes of the assessment; Market Impact and Technology, along with a clear leadership in market presence.
    Learn more »
  • Unified Monitoring™ A Business Perspective
    The enterprise computing landscape has changed dramatically. Virtualisation, outsourcing, SaaS, and cloud computing are creating fundamental changes, and ushering in an era in which enterprises distribute increasingly critical IT assets and applications across multiple service providers.This paper explores today’s computing trends and their monitoring implications in detail. In addition, it reveals how a new monitoring paradigm architecture, that uniquely addresses the monitoring realities of today’s and tomorrow’s enterprises—whether they rely on internal platforms, external service providers, or a combination of both.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments