Hackers use weak passwords
blog.avast.com
blog.avast.com
If a significant fraction of his sample is "hashes he could easily crack" isn't a biased sample? Because it seems likely that the longer, properly hashed passwords are more likely to be the stronger ones...
He's not super clear about where the 40k passwords came from, so they may be a random sample, but it's quite possible that it's just a sampling of bad hackers - he mentions that he has gathered many examples of bots and shells and such, so you can imagine that he's looking at a sampling of 1. hackers whose bots store their passwords in such a way that he can reverse-engineer where they are stored and 2. hackers who store their passwords in plain-text.
That said, if he has 40,000 passwords that boil down to 2000 unique strings, of which only ~400-500 are either good passwords stored in plaintext or not easily crackable, then that means about 35,000 out of the 40,000 passwords he captured were easily guessable (I'm assuming here that there were no duplicates in the "good" password set), which is about 87.5% of his sample.
Yes, that's basically my point. The set of hackers who use strong passwords and the set of hackers who don't well-protect those passwords in their bots/viruses/whatever probably doesn't have a lot of overlap.
Also, it sounds like he couldn't crack (and thus couldn't include in the sample) some of the hashed passwords. Passwords that he can't crack or brute-force reasonably are probably strong passwords. Not having those passwords biases the sample - it's like doing a standardized test when all the honors classes are on a field trip, by removing the top-end you downward-bias the sample and make the overall sample look worse.
(The main issue with using a password manager is that most sites don't support your strong passwords, i.e., you have entered a 50-character password but they still insist on a capital letter or a number …)
Hackers that know what they are doing and care about that particular account use good password policies.
Hackers that don't know any better (perhaps I should use "people who claim to be hackers" to define this sub-set) or really don't care about that particular account, use bad passwords.
Just like the rest of us.
Then again the use case of these passwords doesn't really call for secure passwords, so is it really surprising that they're not overly secure ?
I find this article poorly worded and misleading, telling readers "Hackers use weak passwords just like the rest of us." when it's not about hackers and is not about using weak password like the rest of the world, unless the rest of the world suddenly starts coding malware. Using passw0rd as password for a an easy to remember backdoor password is not the same as using "passw0rd" to access you bank account from the web.
Also, malware is often configured by the operator. If badguy1337 uses someone else's IRC bot code, they are likely to change the password themselves. Same for poison ivy, china chopper, and every other publicly available backdoor/shell.