In 2015 we reported that "123456" had once again topped the annual list of the worst passwords, compiled from passwords exposed in data breaches. A decade later, the lists published each year still look much the same: "123456", "password", "qwerty" and a handful of keyboard patterns and first names sit at or near the top.
These lists are a useful warning, but the real risk is not one obvious password. It is reuse. When a service is breached, attackers try the leaked email and password pairs on other sites automatically. This is called credential stuffing, and it works because many people use the same password in several places.
What current guidance actually says
The most widely followed rules come from NIST, the US standards body, in its Digital Identity Guidelines (SP 800-63B). Several of them reverse habits that many workplaces still enforce:
- Length matters more than complexity. A long passphrase of several unrelated words is stronger and easier to remember than a short string of symbols.
- Passwords should be checked against lists of known breached and common passwords, and rejected if they appear there.
- Forced password changes on a schedule are not recommended. Change a password when there is evidence it was exposed.
- Pasting into password fields should be allowed, so that password managers work.
Three steps that cover most of the risk
- Use a password manager and let it generate a different long password for every account. You then only need to remember one strong passphrase.
- Turn on a second factor wherever it is offered, ideally an authenticator app or a hardware key rather than SMS codes.
- Where a site offers passkeys, use them. A passkey cannot be reused on another site or typed into a fake login page.
Find out whether your accounts were exposed
If an email address of yours appeared in a breach, the passwords used with it should be treated as known. The free service Have I Been Pwned shows which known breaches included an address. Our partner OsintCat offers email and username lookups for people who want to see how an address appears across the open web. Whichever you use, change any password that was used on a breached site, starting with your email account, since it can reset everything else.
No comments yet