Monday, December 01, 2014

2810 - Password mistakes

Well it seems password cracking has become more sophisticated. It used to be just dictionary words were bad. Now it seems that certain patterns are bad also.

(well maybe...)

Here are some new nono's...

-Starting with an uppercase letter followed by lowercase letters
-When a password isn't long enough, adding a letter or two to the base word
-Putting digits, especially two or four of them, before or after the letters
-When a special character is required, using “!” and putting it at the end
-Not using two special characters in the same password

The three most common password patterns are...

-One uppercase, then 5 lowercase, then 2 digits  (Example: Dulith57)
-One uppercase, then 6 lowercase, then 2 digits  (Example: Abugmar64)
-One uppercase, then 3 lowercase, then 4 digits  (Example: Itio1981)


Here are the first 100 most commonly searched patterns according to a company called Korelogic. How do they come up with these lists? By searching for patterns in actual password lists. It seems humans are predictable and 85% of them use one of these patterns. Is your pattern on this list? Mine isn't. Probably just dumb luck.

And it seems online password checkers don't pick up on these patterns.

u - upper case
l - lower case
d - digit
s - special character

ullllldd
ulllllldd
ullldddd
llllllld
ullllllldd
ulllllld
ullllldddd
ulllldddd
lllllldd
ullllllld
ullllddd
ulldddds
llllllll
ulllllddd
llllllldd
llsddlddl
lllllllld
ullllldds
ulllllldddd
ulllllllldd
ulllllds
ulllllllld
ullllldddds
lllllllll
lllllllldd
ullllllddd
lllllddd
ullldddds
ullllllldddd
ulllllsdd
uuuuuudl
lllldddd
ddulllllll
ullsdddd
ulllldds
ullllllds
ddullllll
llllsddd
llllllllld
llllldddd
llllllllll
llllllddd
ullllllllldd
ullllllllld
ddddddul
ulllllllddd
ulllllldds
uuuuuuds
uudllldddu
ullllsdd
ulllllsd
lllsdddd
lllllldddd
ullllllldds
ddulllll
ulllllllds
ullllddds
ulllldddds
ulllsdddd
ullllsddd
ulllllldddds
ulllddds
llllsdddd
llllllsdd
lllllldds
ddddulll
dddddddd
ullllllsd
uldddddd
llllllsd
udllllllld
lllllllllll
lllllllllld
llllldds
llllddds
ulllllllldddd
uuuuuuuu
ulllsddd
ullllllsdd
ulllllddds
lllllsdd
ullllsdddd
ulllddddd
ulldddddd
ullddddd
llllllllldd
llllllldds
lllllllddd
llllllds
llldddds
uuullldddd
ulllllsddd
ulllllllsd
llllllllsd
llllllldddd
ulllllsdddd
lllllllds
lllldddds
ddddullll
uudllldddd

ARTICLE


2 comments:

eViL pOp TaRt said...

Using as many precautions as possible is necessary for banking and credit card sites.

Linda Kay said...

I read that bank and credit card passwords should be changed at least once a month. I'd have a terrible time keeping up, but do change pretty often.