Barely 3000 people used '123456' as their Gawker password(blogs.wsj.com)
blogs.wsj.com
Barely 3000 people used '123456' as their Gawker password
http://blogs.wsj.com/digits/2010/12/13/the-top-50-gawker-media-passwords/
18 comments
I'm not sure this even matters. Gawker accounts are for commenting on inane media stories. If people used the same password for their email, that's one thing, but I wouldn't be surprised if most had a harder password for their email, and resorted to 123456 etc. for less important accounts.
According to this study (http://www.pcworld.idg.com.au/article/355776/study_reveals_p...), the common user reuses passwords everywhere.
The 3000 who used 123456 might be outliers. The real danger of this leak is in those who didn't think of Gawker as being a less important account and therefore undeserving of their primary password.
The 3000 who used 123456 might be outliers. The real danger of this leak is in those who didn't think of Gawker as being a less important account and therefore undeserving of their primary password.
I wouldn't be surprised if most had a harder password for their email
If we were talking about Hacker News, or other programmer-oriented website, then I'd be inclined to agree. Unfortunately, Gawker is all about lowest-common-denominator fluff, and so attracts a lot of (for lack of better term, and please don't mistake this for hubris) "normal people." Normal people don't give nearly as much consideration to these matters as we do, and I'd expect a good majority of these people use the same password (or two) for damn near everything.
It's not uncommon for even technical people to reuse the same low-level passwords across multiple sites[1], but where we understand the importance of our email accounts as being a master key, regular folk aren't always so knowledgeable.
[1] http://www.codinghorror.com/blog/2009/05/i-just-logged-in-as...
If we were talking about Hacker News, or other programmer-oriented website, then I'd be inclined to agree. Unfortunately, Gawker is all about lowest-common-denominator fluff, and so attracts a lot of (for lack of better term, and please don't mistake this for hubris) "normal people." Normal people don't give nearly as much consideration to these matters as we do, and I'd expect a good majority of these people use the same password (or two) for damn near everything.
It's not uncommon for even technical people to reuse the same low-level passwords across multiple sites[1], but where we understand the importance of our email accounts as being a master key, regular folk aren't always so knowledgeable.
[1] http://www.codinghorror.com/blog/2009/05/i-just-logged-in-as...
I got two emails today claiming to be from gawker, telling me to change my password.
Both were phishing emails that pointed to a domain in China and another in India. These guys move fast
Both were phishing emails that pointed to a domain in China and another in India. These guys move fast
I got a seemingly genuine email from Gawker entitled, "Gawker Comment Accounts Compromised -- Important"
Although I don't believe my email address was in the dump.
Although I don't believe my email address was in the dump.
I got that as well. I'm certain my email isn't in the dump (downloaded the torrent to double- and triple-check).
I thought is was strange they used a URL shortener with an uncommon TLD (.kr) to point to the FAQ lifehacker. Seems you'd want to be as unsuspicious as possible in this situation.
I thought is was strange they used a URL shortener with an uncommon TLD (.kr) to point to the FAQ lifehacker. Seems you'd want to be as unsuspicious as possible in this situation.
Actually I just realised that while my email wasn't in the dump, my username was.
I didn't find it myself with grep, but I did find it using this utility: http://news.ycombinator.com/item?id=1999373
I didn't find it myself with grep, but I did find it using this utility: http://news.ycombinator.com/item?id=1999373
I've got the same combination on my luggage
My favorite is always the people who go the extra length and use '12345678'.
Also, why are Jennifer and Michelle the first female names on the list? Are they just the most common names for women?
And is there a story to "monkey"?
Also, why are Jennifer and Michelle the first female names on the list? Are they just the most common names for women?
And is there a story to "monkey"?
> And why, oh why, is “monkey” in the top 10?
I think 'monkey' has always been a top ten password, not just for Gawker users, but I have no idea why.
http://modernl.com/article/top-10-most-common-passwords (2006)
I think 'monkey' has always been a top ten password, not just for Gawker users, but I have no idea why.
http://modernl.com/article/top-10-most-common-passwords (2006)
Why is the title here on HN “Barely”? Because it’s less than 1%?
[deleted]
I think it's supposed to be ironic
It's not less than 1%. Look at the chart. 3k out of 188k
No, that would be 3k of 1.5 million. They would have tried the password '123456' on all of the accounts.
EDIT: I just looked at the dataset and about half of them list NULL as the password. ~3000/748,495 = ~.4%
EDIT: I just looked at the dataset and about half of them list NULL as the password. ~3000/748,495 = ~.4%
My favorite throwaway password is 'nopassword'
I'm curious how many were 'jesus' 'bible' and/or some other obvious one.
A plurality of brute forced Gawker Media passwords are six characters long. Maybe this statistic is valid for all 1.5 million passwords, but that's quite a lot of extrapolation. Taking the easiest 10% of passwords to brute force and basing the data off that?
They mention this fact on the paragraph prior, and then seem to forget about it: "In both cases, the datasets only include passwords that could be decoded and aren’t necessarily representive [sic] of all users."