Statistics of 62K Passwords
codelord.net
codelord.net
I often use enormously unsecure passwords when "signing up" for sites that require registration to continue. I've probably created dozens of accounts around the web with logins like 'qwerty:qwerty' or 'qwer4321:qwerfdsa'. This isn't because I'm a moron, it's because I will never need to access the account again and I therefore don't care about security. "qwerty" is easier to type into a password field twice (for confirmation) than "glxCdsXX3_2".
I would be interested in seeing an analysis of the actual usage of accounts with the most common passwords. It would be interesting to have a bot log into a large amount of cracked accounts and download any usage history or generated data that would indicate how often the account has been used. My guess is that a significant number of the common-password accounts would have the same date for "first created" and "last login". That data could be used to weight the frequencies of the common passwords and paint a much more interesting picture.
Having a closer look at the list, and assuming the dump is organised in some sort of chronological creation order, you can see that all the accounts which use that password are created in several tight groups, share a fairly common username theme (mostly female names), and use a fairly narrow selection of email providers. I would guess they were made by a bot.
> My guess would have to be it’s some worm that resets the accounts it hacked into to it.
Edit: Thinking about his explanation, it doesn't really make sense to me. If that were really the case, those accounts would be more evenly distributed through the list - yet they are tightly clustered, which leads me to think they were created in groups (guessing the list has some sort of chronological order).
Where are you looking at the clustering?
My take is that this depends considerably in your target audience, I'm not disclosing which team I'm a member of, but if you run the same analysis to come up with ideas on how to enforce users to chose better passwords, you'll see how different the result are going to look.
tableau public tends to be a little slow, tho.