A better analysis could be done if it were compared with another password leak from another site.
But even if there's no better analysis, the best analysis may still be severely broken.
A better analysis could be done if it were compared with another password leak from another site.
But even if there's no better analysis, the best analysis may still be severely broken.
I think it's debatable actually - while intersecting the list with another does give you less bias, it also reduces the sample size immensely (as happened in the 2011 analysis I linked to), so there are trade offs in both directions.
I'm not claiming that I know exactly how many accounts reuse passwords - I am suggesting that, based on my estimate, it is more than half.
The evidence (that I've linked to) supports this. There are other studies which show upto 60% of password reuse: http://www.troyhunt.com/2012/07/what-do-sony-and-yahoo-have-...
If you can produce a better estimate please go ahead.