It is a hacker’s dream. Even in the face of repeated warnings to protect online accounts, a new study reveals that “admin” is the most commonly used password in the UK.

The second most popular, “123456”, is also unlikely to keep hackers at bay.

It’s not just a problem here – Australians, Americans and Germans also use “admin” more than any other password when accessing websites, apps and logging in to their computers. Around the world, “123456” emerges as the most popular.

  • Dagnet@lemmy.world
    link
    fedilink
    English
    arrow-up
    36
    ·
    28 days ago

    Luckily for me my password is ******

    Edit: weird lemmy automatically replaced my password with ‘*’

  • 7U5K3N@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    30
    ·
    28 days ago

    The second most popular, “123456”, is also unlikely to keep hackers at bay.

    That’s what I use on my luggage

      • deranger@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        28 days ago

        The more factors, the less secure. Each one you add is another potential exploitable authentication method. It’s only as secure as the least secure MFA method you add.

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        28 days ago

        I mean, how many factors do you advocate for? Two is generally plenty as long as they are good ones.

        E.g a passphrase protected ssh key is solid. Similarly protected passkey is good. A TOTP with password is… Not terrible I suppose… SMS would be pretty bad…

      • Fizz@lemmy.nz
        link
        fedilink
        English
        arrow-up
        2
        ·
        28 days ago

        Either or as long as theyre stored encrypted and decrypted on device.

  • Ex Nummis@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    28 days ago

    I’ve “hacked” web apps by logging in with “user - password” or something equally inane.

  • shalafi@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    28 days ago

    Picked up a keyboard at the thrift with a pink sticky note on the bottom:

    user:admin

    pass:password

    Yes, someone had to write that down.

  • Jimbabwe@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    5
    ·
    28 days ago

    Invent your own hashing algorithm. It’s easy, fool-proof, secure, and reusable without compromising security.

    Here’s a few examples: ebay.com password is moc.y4b3-saltyboi69 lemmy.world password is dlr0w.ymm3l-saltyboi69

    (These aren’t real btw)

      • Zaktor@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        3
        ·
        28 days ago

        Most compromised passwords are used by script kiddies in mass attacks, not targeted attacks by elite hacking squads. If a password fails verbatim, they just move on to the next compromised account of millions, not develop pattern recognition software to try to figure out replacement candidates for each website.