Most common passwords list from 3 databases
blog.jimmyr.com
blog.jimmyr.com
singles.org users commonly use passwords with religious meaning, like "jesus", "pastor", and so on. Apparently this is a site that appeals to the religious folks.
phpBB has things like "phpbb" and "password". Their forums force people to create an account they don't want, so they pick a dumb password. (I had to ask a phpbb question once. I think I used 1234 as my password.)
Finally, Myspace is Myspace, and has commonly-ocuring gems like "poop" and "nigger1". Ah, high school kids...
Some of the other ones are puzzling. "trustno1" is from the X-Files, but does anyone know where "letmein" came from?
No, the real issue is password questions. "What is your mother's maiden name?" "In what city were you born?. Those always seem like a security hole, so I choose a random question and just remember that the answer to all my security questions is "the landed gentry". That's fairly secure, right?
Unfortunately this is so similar to standard phishing attacks that I'm afraid the good would be offset by the bad of reinforcing user behaviors that its ok to click through on 3rd party notices like this.
The best protection is not a good password. It's having something that's not worth stealing.
At the moment all I do is insist on a minimum length but it doesn't seem as though it would be all that difficult to add checks for common passwords.
interesting.