The hacking of a web site last month that resulted in the theft of 32 million passwords has offered security analysts a rare opportunity to study password-selection patterns. A hacker breached the firewall of RockYou, a site that offers widgets and applications for social-media networks, and harvested the passwords. Later the hacker posted the passwords online without identifying the users.
When Imperva, a California-based data-security firm, analyzed the passwords, it found that users made alarmingly simple choices. The most popular password was 123456, which was chosen by 290,731 users. Another 61,958 users chose Password as their password, while 17,542 chose abc123.
Other unsophisticated passwords included iloveyou, qwerty and the name of the site, rockyou.
While the data on RockYou may not be an identity thief’s dream, Imperva, in a white paper released Thursday, cited studies that show “about half of users use the same (or very similar) password to all web sites that require logging in.”
Simple passwords using sequential numbers or letters are a hacker’s delight, Impreva said, because they are easily vulnerable to a brute-force attack, in which the invading computer enters multiple randomly chosen passwords until it hits the jackpot.
“The combination of poor passwords and automated attacks means that in just 110 attempts, a hacker will typically gain access to one new account every second, or a mere 17 minutes to break into 1,000 accounts,” Imperva said.
Imperva recommends that users follow NASA guidelines, which suggest passwords longer than eight characters with letters (uppercase and lowercase), numbers and symbols, and without using a slang word, a name or word in the dictionary, or any part of the user’s e-mail address.
The hacking caused some red faces at RockYou, formerly called RockMySpace. The site now carries an advisory telling users to change their passwords for e-mail and other online accounts if…