Top 200 Most Common Passwords
nordpass.com
nordpass.com
People create weak passwords for services which shouldn't be authenticated in the first place.
If you're throwing up a registration requirement just to read public content (say, as the BBC seem to have begun doing in the past month or so), then yes, a large number of people will offer a bogus userID and the password "password", or a semantic equivalent.
(If they bother using the service at all.)
Overauthentication is itself a manifest security problem, because you're now effectively requiring bad keys be used.
See also: Twitter, Quora, and any number of other regwalled services. (I simply avoid using them.)
That said: organisations should reject any of some reasonably large number of well-known passwords. Where large should be well into the thousands if not millions by frequency of noted use.
That said, I agree a low upper limit is odd, and ideally it'd check for entropy so a long string of lower case letters would be accepted.
I think I added an exclamation point to it as well at some point.
Sports teams, taken together, might be even more common that "password" and its variations.
weird... wonder why
Is this a reference I'm not familiar with? Otherwise I wonder how much of her higher numbers (outside, say top 20) are effectively just noise
Seems like it's a reference to AFU establishing themselves in Liman and 1000s of russian soldiers backing down? That's all I could find https://theins.ru/en/news/254974
Another way to look at this is that the salt prevents information leakage from the hashes. Even if the same password occurs dozens or hundreds of times in the same database, unique salts will ensure that every hash is unique.