advertisement
Looking for something on the site? Search for it here! Also see Clark's Greatest Hits

Aug 21, 2009 -- The 10 most common passwords

With all the talk of high-level hacking, it's easy to forget that it is we who make ourselves most vulnerable on a very individual level. PC Magazine recently compiled a list of the 10 most common passwords in the United States today. Do not use these on confidential e-mail accounts!

1. password

2. 123456

3. qwerty

4. abc123

5. letmein

6. monkey

7. myspace 1

8. password 1

9. blink182

10. (your first name)

These are the first passwords that a criminal would try when attempting to hack your account. Other types of passwords you want to avoid are birthdays and the names of your children or spouse.

Clark has had some particularly creative passwords over the years. In the past, he's used an employee ID number from a company he worked at in the '70s. Then he came up with an even better idea, which he can't divulge for obvious security reasons!

The key is to create a password that is unrelated to anything someone might be able to find out about you if they were digging into your background. Tricky alphanumeric passwords -- ones that include both letters and numbers -- can work well.

Unfortunately, Clark won't be able to answer any questions submitted via commenting. If you have a question, please try posting it to our message boards.

Avg. rating: N/A

What others are saying

  • Password
    I'm a guy so no one would ever guess that my password is Jackie.
  • passwords
    I think the best way is to construct a short memorable sentence and use the first character of each word. And some words can be either the letter or numeral like too (t or 2)for (f or 4)
    I think Clark likes this way too = password - itcltw2
  • passwords
    I think the best way is to construct a short memorable sentence and use the first character of each word. And some words can be either the letter or numeral like too (t or 20)for (f or 4)
    I think Clark likes this way too = password - itcltw2
  • passwords
    you mentioned good ideas for passwords. One that I have used in the pass was to take book titles that I may not like and changing them with charcter substituion and numbers. Also many user do not know that they can set a bios password that will not allow a computer to boot at all unless they know the password to unlock the bios. Unlike OS passwords, this can not be bypassed with an installation disk. another one that works well too is driver license numbers. They are long, tedious, and require more research to figure out. Using numbers or even info that you are trying to remeber also works well. Some funny passwords that I have seen is fubar3 and snafu64
  • i think this is a good article
    for referance
  • Passwords
    I have several strategies but one I haven't seen here - I use a string of 2 foreign words, such as locollama. I maintain a written password list with codes for each password.
  • Passwords
    I use streets that we lived on years ago, but adding a house number from another city where we lived. Recently I discovered my grown daughter was using some of the same passwords. But we keep changing the streets and numbers.
  • For years, I have kept a separate address book next to my home computer. In it I list website names and the un/pw for the site. so many sites now have different requirements! "Must use upper and lower case" "must have a special character" "must be exactly 8 characters long"...ugh! This has worked well for me and I have never been compromised.
  • Monkey?
    Monkey?

    I've had "monkey" used in aliases or usernames, but not in passwords.

    Monkey?
  • passwords
    i used passwords from a favorite song, example.AMERICATHEBEAUTIFUL9
  • passwords
    this is so very true.
  • An "infinite" number of passwords
    Check out www.keepass.info. Passwords can be saved in an encrypted file that requires a password to get in, and will generate a new random password for you to use when registering at new sites. Now, if a single site is hacked, it doesn't jeopardize any of the other accounts!
  • Create a password formula
    You can create a unique and totally secure password for each site you visit, and never forget them. Just create a formula based on the web sites name.

    Say your personal formula is to take up to the first 8 letters of the web site name, and then add a "15" before it and capitalize the last letter. And do that every time.

    Using this formula my password for yahoo would be "15yahoO" My password for Clark Howard would be "15clarkhoW"

    Each password completely unique and unguessable based on your own personal formula.
  • Password help
    If you insist on using the same word over and over, but want to add some security, try substituting numbers instead of letters. An 'e' would be substituted by a '3' and an 'i' by a '1' for example. Then even an easy password like 'letmein' becomes 'l3tm31n' and will become much harder to crack.
  • pass word
    If you make your paswords list up ahead of time you will be more creative and less apt to fall into a routine in the listing, but where do you keep the list.
  • paswords
    I write mine down in shorthand. Most people can't read shorthand.
  • passwords
    I just write the password on a post-it and stick it right on the screen. That was easy!
  • passwords
    I use the first letter of each word in an easy to remember sentence. Characters and numbers can be added as well.
  • Passwords
    I make all my passwords in random characters and letters and numbers. I keep all passwords not memorized in some place in my home.
  • Safe password strategy
    None of my passwords are written down, anywhere, yet I easily remember >10 separate and totally distinct P/Ws by posting very short hints in the bookmark that have no relation to the P/Ws themselves, but they mean a lot only to me. To list the key would jeopardize the system. You figure it out. Good luck.
  • passwords
    I use the first letter of each word of a nursery rhyme - Humpty dumpty sat on a wall - capitalizing the first letter, and add "@ 10" for the end of any password I create. Hdsoaw@10
  • passwords
    I keep a folder with all the passwords and user ids for each account I create (craig's lisit, ammazon, etc.) because I could never remember
  • My password creation
    I’ve been using what was recommended to me by my friend – computer expert.
    Create a sentence you remember, for example I will love my white dog forever. Then use the first letters to create your password – iwlmwdf. If they ask for a number I add after ‘forever’ number 4. (iwlmwdf4).
  • The best password combo
    I think it's best to use all of the following: Uppercase AND lowercase -- numbers AND punctuation (ex: period, exclamation point). Not all websites allow punctuation, but if they do - use it and your password will be VERY hard to crack the code.
  • Combo passwords
    Without getting too complicated, you can put two words together that separately mean something to you. Easy to remember yet hard to crack.
  • w
    [verb] [noun] [single letter] [two-digit number] [punctuation]

    poke car y 56 !
    slash book l 83 .

    Catchy, easy to recall and random enough to be safe but memorable.
  • Ironclad password
    I must have close to 150 accounts that require passwords, and I use the same password for all of them: a string of 10 asterisks. It's easy to remember and I've only had my identity stolen four or five times in the past two years.
  • ROBOFORM ROBOFORM
    I highly recommend ROBOFORM.com. It uses military encryption on your passwords, plus it will generate a good one for you, and automatically fill it in when you visit a particular site. Plus you can print them out, and sync them online, so if you computer dies, you can just reload them onto the new computer. Best program I've ever added to Internet Explorer.
  • Password
    I actually HAVE been doing this for over 20 years now. Some of these ideas sound nice but if you had even close to the number of passwords I have to remember you would find your self locked out OFTEN going hmmm cap this convert WHAT? Get about 5 nouns you can always remember. Then make your self a start and end to them that are numbers or punctuation. !(cat)! 1234567890 is probably the most common 10 digit wep and password1 the normal password.
  • Passwords
    All my passwords are random characters, letters and numbers. I keep my passwords in a place so that I can remember them.
  • Passwords
    I use a combination of numbers and letters form co workers and myself, basically for example I use the badge number of an office I used to work for, the 2 digit number of the birthday of someone NOT close to me and dates and or letters that are from people close to me but I so nto use the exact dates, or letters assocuiated to anyone but a formula I concocted all on my own, whick of course I will not give that formula here. I made it up myself but anyone close to me or that I worked with will ever be able to figure it out because it is my own madness so to speak. ALso NVER use p@ssw0rd......I" used to work someplace and that was the password for EVERYTHING and someone figured that out!
  • Here is a simple and memorable method for secure passwords...
    I am a computer tech and as an alarm dispatch operator. I see security passwords all the time that are horrifyingly simple, given that lives can depend on them. I create a simple sentence relevant to my activity: "I go to clarkhoward.com for money info." This becomes "I g 2 C H . c 4 $ i ." (Spaces for emphasis on individual characters.) I generally keep the first letter of each word, capitalize named objects, convert similar words into numeric homophones (won/one, to/two, for/four, ate/eight), convert relevant concepts into symbols (at/@, number/#, money/$, star/*) and retain punctuation. Of course, you want something easy enough to remember and convey if advising your alarm company of a false alarm or emergency, but there are no excuses for not having a simple, memorable password for your data.
  • hundreds of different pwds, none written down or saved!
    OK article for the clueless I guess but these stories are running for years now.

    I picked up this trick years ago, working network security - an easy compromise between the two extremes. I use unique (or almost unique) passwords for different sites or systems. Nothing is written down or saved anywhere (e.g. no programs involved). Recalled instantly. I always get in, and rarely get locked out. How?

    My pwds are made from two parts- one part unique to EACH website or service, one part common to all my pwds. Has to be OBVIOUS to you and instantly recalled and applied.

    For example: clarkhoward.com. = CLA. Plus the common element (say xyz99). Pwd for that site is "CLAxyz99".

    You could do it different ways- the point is to be consistent. Email is EMAxyz99 (email) or OUTxyz99 (outlook), etc.

    Even if someone gets one pwd, they won't be able to hack into other systems. Unless they uncover the pattern (which I made clear above on purpose).

    If you stick to 8 characters (exactly), combine CaSe and Number5 you meet 99% of the requirements or limitations different websites try and force. My rule is add $ if special char is req'd (rare). Avoid specials (!@#$%^&* etc.) otherwise since so many systems will not support it (breaks your pattern).

    But I have used this for 10+ years now and have had to write down only a handful of pwds. Combined with a bizarre username you can register everywhere (i.e. whiteZ123) and you have to commit VERY LITTLE to memory. As mobile as you are, no license fees or batteries required.

    I also like to obfuscate about the "questions"... my favorite pet? REPEAT. Answer that to someone on the phone.

    Common? add admin-adm1n
  • Password ideas
    I sometimes use the registrey of Starships. And no, I do not use the ENTERPRISE! :-)
  • Passwords
    Pick out an animal name and spell it differently (zeebrah, munkee, donkee, dawg, kaatt, for example) and add numbers. OR, how about a special date with one of your initials after each number, such as 03x29y49z. OR your hero's name: 1CLARKHOWARD1, for example :0)
  • passwords
    Baloney! When I become king of the world each person will have four things: only 1 key, only 1 number, only
    1 password, and only one opinion - and that'll be Mine.
  • Passwords
    Ever heard of Perfect Paper Passwords? FREE from GRC.com under services. Passwords are FREE but you have to supply your own paper and ink!
  • passwords
    Ya got pets?...... Does your car have a name?.........Use these names plus numerals.....I have never had a problem!!!!!!!!
  • password
    here's my idea - every year i pick a company i like and use the stock symbol. then i choose a day from several years ago, and write that date, and the corresponding stock price, i.e. you pick general electric (stock symbol: GE), the date 2/10 (210) and the stock price at close on that date 5 years ago (3250). now arrange it date, company, price - 210Ge3250. You can change out caps or not if you want/need. every month, just pick a new date, or so its easy to remember, same date (10th) just the next month.
  • x
    "jesus" and "money" are also very common.
  • my brain is full
    I let LastPass generate random passwords. I only have to remember one master password. And it's free!
  • Passwords
    Another online password generator:

    http://www.pctools.com/guides/password/
  • Password
    Use your license plate number. That way you will remember it as well. Hopefully, it has both numbers and letters in it.
  • Passwords
    My suggestions--don't use anything related to your family, such as parents' names, places of birth, marriage or death, etc. Many times these can be found on the internet through people finding or other programs.

    For password creation, try this--take a sentence about yourself, like "I lived in New York City eight years." Use the first letter of each word so it looks like IliNYC8y, and there's your password, minimum 8 letters and has one digit. You can expand on this idea to create any type and number of passwords. Works for me and since it creates a jumbled password, is harder for someone to break.
  • Easy to recall and non-words...
    I like to use the first letters of the names of favorites pets I have had plus a number I can remember. Long and complicated passwords are dangerous because they almost always have to be wrote down. I do like the 2 dollar bill serial number idea...
  • my favs
    I'm from OK so have enjoyed using tribal names given to towns with a number. or I sometime use a phrase like 4myage or 2theroof
  • 2 thoughts
    One, If you have yahoo, rocketmail, ymail or anything yahoo for email, Change your zip code in the profile. Anyone can get your P/W if they know your zip code, birthday, and your screenname. From there, they can have forgotten P/W's for other accounts emailed to the hacked account. If they change your email P/W and zip code, you are locked out. Two, try a license plate and a model of a car for a P/W.
  • passwords
    i use and reuse a series of words that are not in the dictionary and contain special chars. I like the suggestion of using a 2 dollar bill's serial number... medical conditions and medicine dosages are good too.
  • Encrypted Password Database
    Use of an encrypted password database is encouraged assuming that the password to get into it is complex enough where no one can guess it. http://passwordsafe.sourceforge.net/ is what I use. cheers.
  • To Jeff
    Jeff wrote "Good job to PC Mag increasing the number of hackers out there by getting the most popular passwords from email providers and.......then publicly announcing them. Good job to you too Clark."

    Jeff - you don't think hackers already know this list? It makes more sense to expose it and let normal people know that their passwords are probably not too secure. Of course hackers already know this list. They probably know the top 50 passwords. Use your brain.
  • deducing pw on the fly
    i use a very simple system that renders a different pw for each web site based on site name, it does not need to be remembered or stored.
  • Passwords
    I worked in network security for 20 years, for clients like major banks & credit cards. Here's the scoop:

    - minimum length = 8 characters. More is better
    - alphanumerics are just OK. Adding special characters is better.
    - there is no such thing as a safe password (unless you use a one-time password scheme, which is too long to describe here so Google for it).
    - bio-recognition devices seem like a great idea but all of the consumer variety ones have a password override; what good is that?
    - anyone who wants in badly enough will get in. It's simply a matter of time. The trick is to set your security to make it not worth the trouble. That means strong passwords, but hardening your machines, too. Learn about firewalls, don;t just trust them "out of the box".
    - Most often it's not our fault our information gets stolen, but because it lives on some company's machine that gets hacked and was poorly secured, so...
    - open a new bank account for the minimum amount and get a credit/debit card. Use that card for your on line purchase, transferring enough into the account to cover your costs, and only that much.
  • Low Tech Password Encryption & Storage
    To create a low tech:
    I put together a low tech process for keeping passwords "out in the open" for a friend and thought you might benefit from it as well. It's so radically simple that you can keep passwords written down on a piece of paper in your wallet (or purse). In fact, you can even post them on your monitor at work!

    It's simple and "encryption" just involves 2 steps. Let's take the password KChiefs (a friend lives in Kansas City).

    Step 1
    Reverse the case: kcHIEFS

    Step 2
    Move each character forward in the alphabet by one character: ldIJFGT

    There you have it: KChiefs encrypted is ldIJFGT. That's the password you carry in your wallet.

    Now to "decrypt" it, just reverse the process: Move each character back one. Then reverse case. That's it. And it'll work with every password you currently have. (If a password contains special characters like !, %, @, ~, *, etc., just retain them as is.)

    You can modify the process by moving ahead with more characters, say two instead of just one. In this case, kcHIEFS would be meJKGHU.

    Or you can start the process by moving back one or more characters rather than forward. Just keep it simple and easy to remember and apply.

    To store and hide a low tech in "plain sight":
    Open Windows Explorer (Windows key + E). Right-click inside a folder and create a new text (.txt) document. Put your passwords in it, save, and exit. Now, change the extension to something like dll or sys. If prompted to make the change, click OK. Now it will not stand out if any snoops around your PC. Just remember where you put it and what you named it. When you want to reopen it, simply change the extension back to .txt and it will open with NotePad when double-clicked.
  • Password
    I spell names backward,and them and a birthdate at the end example: leahciM66
  • good idea for a password
    I use an alpha numeric password that includes 4 numbers from a phone number I remember from the past, along with the 3 initials of a company I used to work for.
  • Passwords
    Years ago I opened the Sunday paper to a random page, closed my eyes and pointed. Variations of the word my finger landed on have been my passwords ever since.
  • Passwords to avoid
    Good job to PC Mag increasing the number of hackers out there by getting the most popular passwords from email providers and.......then publicly announcing them. Good job to you too Clark.
  • All this makes my head hurt
    I created a really good password, but I can't remember what it was.
  • Passwords
    I generate my own combination of alpha-numeric passwords with random upper and lower case letters and numbers and usually with the maximum number of characters allowed. There are usually no complete words. I do write them down and keep them in a secure place too, so I can find them when I need them.
  • Passwords
    Sometimes they ask you to answer a question like "where were you born" or "what is the name of your high school " ... these answers can be found in your MySpace or Facebook profile pages, so this is what you should do. Substitute an aswer that can NEVER be guessed, If they ask what city you were born in - use a word that is NOT a city like " radiator" or "refrigerator" ... If they ask for your mothers maiden name do the same thing except use the name of a medical condition like " carcinoma or heart attack or pneumonia ... NO ONE WILL EVER GUESS THESE.
  • Password Protection
    I often use words in foreign languages that I speak and aren't similar to English and often don't use the Roman alphabet, but rather, transliterate them into English characters.

    Also, if you have a file with all of your passwords saved, on Word or Excel for example, make sure they are encrypted with an impossible to guess password with a mixture of letters, numbers and symbols with more than twenty characters long. Common encryption software are Bit Locker for Windows and Truecrypt. I know that Apple has one specifically for Macs, but I can't remember what it is.
  • My method
    I have a couple of phrases that I really like. The password is the first letter from each word in these phrases. I capitalize certain words and then throw in a few random characters in certain spots that are significant to me. Yes, this is a lot of personal info, but getting it in the correct order is pretty difficult.
  • Password Protection
    do not store passwords and logins in files on your harddrive named "passwords" or "logins". Hackers that make it to your harddrive look for these file and folder names.
  • Passwords
    I use names of Etruscan gods with digits interspersed.
  • Passwords
    I use randomly selected medicine names and dosages ie levothroxine25mcg
  • Passwords
    Easy Solution. Go to Robo-Form and get their free program, which will automatically assign random passwords for up to 10 sites. Anymore than 10 and there is a fee.
  • passwords
    I like using something easy to remember, but break into the middle with a well known (to me) number sequence, such as: Mon0809day
  • passwords
    A trick I use is to pick a word, normally how I feel at the time, and subsitute numbers and special characters for some letters. I also try to keep my passwords at a minimum of 8 letters, which include uppercase, lowercase numbers and special characters.

    Example:

    monday sucks = M0nd@y$uX!
  • Passwords
    Don't use your pet names. Eons ago when I sold on ebay, someone wrote me several times pretending to ask for info. Told me he was setting up a website for pets and was collecting pet names, Duh, I gave him mine. Yep, he got into my account and
    took money. Luckily, I noticed and reported him.
    Back then, they gave you the password online, back in the early 90's.
  • passwords
    An organization of which I'm a member has a creative method for choosing passwords : they think of a song title, then use the first letter of each word in the title, then a number for the year. For example, use the song : "Boom, boom, ain't it grand to be crazy?" Password would be bbaigtoc9
  • another common password is
    ncc1701 : )
  • Bad advice!
    Don't use a town name plus a year. A quick and easy dictionary scan attack can circumvent single and dual word passwords in under a couple of seconds. Passwords should be at least 16 characters (longer if its critical), contain upper and lower case, letters and symbols, and not contain words from the dictionary, including words which replace characters (@ for a, for example). Don't follow those rules, and brute force methods can crack your password easier than you might think.
  • Thanks for this USEFUL list.
    I'll first go through this list to break into accounts before I try other things.
  • get a 2 dollar bill and use the serial number on it
  • passwords
    Someone emailed me all of their passwords one time. She thought she was emailing to her husband, but oops.. not only passwords, but the account numbers to go with them. Good thing I was honest, but that is stupidity.
  • Hell Another Old Guy just write your passwords in the back of an old book and put it back on the shelf with all the other old books.
    alphanumeric would be a good password though.
  • Another secured password thought
    I use a random 14-18 digit alphanumeric password for each website etc., and use the auto-enter feature on Firefox to put them in for me so that nothing needs to be remembered. (I also use a Master Passcode to secure this feature.)

    I also keep all passwords and important information in an PGP-encrypted text file just for safekeeping. When passwords are occasionally changed, I update this file and re-encrypt.

    Worth noting: the computer I use also has an EEPROM-based boot-password feature as well that cannot be bypassed using hardware-jumpers. This further secures all this information if the entire computer is ever stolen.
  • Why just a word?
    Type a short sentence. Use proper capitalization and punctuation, and replace a couple characters with numbers.
  • Another Suggestion
    BlackBerries have a random password generator. I've used those quite a bit, and I manage to remember them.
  • site for random passwords
    I use a website to create random passwords. Once I find one I like, I type it 10~30 times in a row in notepad until it I remember it (usually by feel of how it's typed).

    http://www.pctools.com/guides/password/

    I'm not creative enough to think of my own passwords so this seems to work pretty well thus far.
  • My password
    I use the town my mom was born in, plus the year she was born. Easy for me to remember, but no one would ever guess it.
  • Passwords
    Never write down your passwords. Make it unique so you will remember it but not crazy like 'wuvfn80372beu2398023h' so that you have to write it down.
  • Passwords
    For a new password use the current time of day and plus the month or day name. For example:
    020004friday or august020004. Be sure to write them down.
send to a friend  view as printer-friendly  RSS feeds
advertisement
advertisement
THIS WEEK'S POLL
advertisement