Skip to main content

Report shows many web surfers are still using ‘123456’ as their password

For some reason, many web surfers accessing the internet don’t appear to be listening. Despite warnings by experts and countless reports of hacking, identity theft, online fraud, and more, there are people still using “123456” as a password. That simple sequence of numbers reigns king on the new top 100 worst passwords list of 2017.

According to numbers provided by SplashData, the use of “123456” as the No. 1 bad password hasn’t changed in years. The firm provides its list of the top 100 worst passwords each year, and shows that “123456” officially unseated “password” from the top spot in 2013. Since then, 123456 remains at the top of the list followed by “password” and several other common words and numbers.

Recommended Videos

California-based SplashData provides security applications and services, including its SplashID Personal Password Manager, and its TeamsID Business Password Manager. The firm releases its annual list to encourage internet surfers to use stronger passwords. The firm’s data supposedly derives from millions of leaked passwords discovered throughout the year.

Here are the top 10 worst passwords used on the internet starting from SplashData’s very first report in 2011:

2011 2012 2013 2014 2015 2016 2017
1 password password 123456 123456 123456 123456 123456
2 123456 123456 password password password password password
3 12345678 12345678 12345678 12345 12345678 12345 12345678
4 qwerty abc123 qwerty 12345678 qwerty 12345678 qwerty
5 abc123 qwerty abc123 qwerty 12345 football 12345
6 monkey monkey 123456789 123456789 123456789 qwerty 123456789
7 1234567 letmein 111111 1234 football 1234567890 letmein
8 letmein dragon 1234567 baseball 1234 1234567 1234567
9 trustnot 111111 Iloveyou dragon 1234567 princess football
10 dragon baseball adobe123 football baseball 1234 iloveyou

As the chart shows, “password” and “123456” are locked in a heated battle for the top spot. “12345” and “12345678” fight for third place while “qwerty” and “12345678” battle for the fourth position. One of the troubling factors is that the top 10 consist of similar words and strings of numbers over the last seven years, including “football,” “baseball,” dragon,” and “iloveyou.”

But SplashData’s annual reports don’t mean everyone on the planet is using these passwords. The company is merely pointing out bad password use in hopes that future lists will eventually wither and die. But given that these words and number strings are pulled from millions of leaked passwords each year, you can see why hackers are having a field day breaking into online accounts.

Most major websites now demand passwords consisting of upper and lower-case letters, numbers, and symbols of a specific length (character count). They even offer two-step authentication that requires a mobile device to authorize logins. But as the lists shown above illustrate, the top bad passwords consist of all letters or all numbers.

Moreover, security experts will warn that you shouldn’t use passwords that are directly related to your life, such as using your birthday, favorite movie, child’s name, and so on. Passwords should essentially be phrases that mean absolutely nothing, but can be easily remembered. “Sciss0rzCutzCh1ck0nz” could be a tough nut to crack.

Of course, using a password manager like LastPass or 1Password to handle all your accounts and passwords is an ideal security strategy as well. These services are subscription-based but eliminate the need to manage multiple passwords for multiple accounts.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
This Lenovo ThinkPad is usually $2,059 — today it’s under $1,000
The Lenovo ThinkPad L13 Yoga 2-in-1 laptop in tablet mode.

You can enjoy the best of both worlds between laptop deals and tablet deals if you go for a 2-in-1 laptop like the Lenovo ThinkPad L13 Yoga Gen 4, which is currently on sale from Lenovo itself at 54% off. Its estimated value of $2,059 may seem a bit too high, but in any case, it's a smart purchase at its discounted price of just $931. You'll have to be quick in finishing the purchase process for this device though, as it may be back to its regular price as soon as tomorrow.

Why you should buy the Lenovo ThinkPad L13 Yoga Gen 4 2-in-1 laptop

Read more
‘You can’t lick a badger twice’: How Google’s AI Overview hallucinates idioms
Samples of Google AI Overview errors.

The latest AI trend is a funny one, as a user has discovered that you can plug a made-up phrase into Google and append it with "meaning," then Google's AI Overview feature will hallucinate a meaning for the phrase.

Historian Greg Jenner kicked off the trend with a post on Bluesky in which he asked Google to explain the meaning of "You can't lick a badger twice." AI Overview helpfully explained that this expression means that you can't deceive someone a second time after they've already been tricked once -- which seems like a reasonable explanation, but ignores the fact that this idiom didn't exist before this query went viral.

Read more
You can now try Adobe’s new app to digitally sign your artwork for free
Adobe Content Authenticity app graphic.

First announced in October, Adobe's Content Authenticity app is now in public beta, and anyone can try it for free. The app allows people to add "Content Credentials" to their digital work -- invisible and secure metadata that shares information about the creator. AI can't edit it out like a watermark and it still works even when someone screenshots the original file.

You can add various information to your Content Credentials, such as your name (which can be verified via LinkedIn) and your social media accounts. You can also express your preferences toward generative AI training. This is an experimental feature aiming to get a headstart on future AI regulation that Adobe hopes will respect the creator's choice regarding training data.

Read more