Show HN: 5+ Billion Passwords in Order of Most Popular
github.com
github.com
I'm also going to attempt to attribute the sources to given countries or at least language families. The list as it stands has a heavily US-centric bias.
I plan to grep through it and pull out things like Cyrillic or Arabic characters, and then repeat the process using only those characters. That's not to say that everyone who uses Arabic or Cyrillic characters is guaranteed to use them, but it's more specific.
If "password" is #2 in the world, perhaps пароль (password) will be the #2 most popular password with Russian Cyrillic Characters
There should be libraries in any language used to develop systems which validate user-entered passwords.
(Promptly changes around variables in quadratic equation for the umpteenth time, leaves the rest of the password the same.)
When I'm met with periodic expiration, I employ constant direct password assistance as a means of unpopular two-factor authentication, to piss people off, and stir the pot.
I then fail my password reset as many times as necessary to recover my preferred password for that system, to enforce to freedom of password selection.
I control my password. Me.
Not you. Me.
edit: on 2nd thought looks like a bloom filter for 5B entries at p=0.01 would be ~5GB, so not exactly convenient
Popularity was based on how many they appeared in files that had all duplicates removed (in reference to themselves)
The smallest file had passwords that appeared 75+ times, and the largest file had passwords that appeared 2+ times.
The top 195 Thousand (which appeared 25+ times in analysis) clocks in at 803kb as a text file with nothing but the passwords themselves
The main page contains links to Mega.NZ alternative downloads. Will be fixed shortly, apologies for the inconvenience.
Perhaps next rev I'll only include the .7z (smallest) and greppable formats.
Two out of the 12 aren't, but every wordlist can be downloaded via torrent in at least 3 compressed formats, including .7z
All you've done is shuffled around the most frequent cases to the beginning, which is great if that's what you are looking for, but now something else occupies the last slot and that case is just as bad as before.
The real solution is to see these files as input to an indexed table so that you can get to the entry you want in log(n) time.
Well, that's pretty much how one would try to crack a password using a wordlist.
EDIT: If the goal is to crack a bunch of properly hashed (PBKDF2, scrypt, etc.) and salted passwords then a lookup table is not very practical.
That's not why these lists are made public (though I can appreciate the fact that they are 'dual use').
Also see: Security through Obscurity.
[0] Google's notorious Project Zero, for instance.
It's a fairly specific term so trotting it out for everything makes it pointless and obscures its actual meaning. Every time someone misunderstands something about information security (or someone thinks they do), someone else comes along and says 'Security through obscurity!' or 'Trusting trust!' or something about source code. It turns these things from terminology and concepts into magical-sounding incantations that really just mean 'I disagree/don't like this'.
This is analogous to the more familiar overuse of 'ad hominem' and 'straw man' and so on. It's not a good thing.
It's not like bad guys don't already have wordlists, or that they are new in any way. Having good ones available, in the open, for everyone to use, provides a net benefit in the long run imo.
Year after year people still use the same passwords that were the most popular for the year before. I think we should make it as obvious as possible that it is worth your time to make secure passwords.
I think people know that they shouldn't use "password" as a password, but it just needs to be made very clear through safe means (such as publishing wordlists that don't have any associated user data) that it leaves you very vulnerable. Many people simply haven't stopped to wonder how secure their password is.
My goal with this project is to flip the status of the passwords on the list - and make them the LEAST likely to be used.
Yeah, like that is going to stop people from doing nefarious things with this info. If you feel the need to post this screechy, all caps disclaimer, maybe rethink your project entirely?
Geez.