Password Insecurity: An Analysis of Gawker User Passwords

December 15, 2010

An analysis by the Wall Street Journal of the stolen user data from Gawker media proves that many users don't take password security very seriously. At all. That data was swiped over the weekend by a hacking group called "Gnosis," who managed to gain access to e-mail addresses and passwords of more than a million Gawker users.

Gawker's sites have been compromised, causing users to reset their passwords to sites such as Lifehacker, Gawker, Gizmodo, Kotaku, and Jezebel. The Wall Street Journal analyzed some of the hacked Gawker data that has been released to find trends in people's password selections. They looked at a sample of 188,279 passwords made public by the group. The list proved that a lot of users chose passwords that were just stupid. The most popular password was "123456," followed by "password." Other foolish choices included "lifehack," "qwerty," "monkey," "letmein," "cheese," "trustno1," and "passw0rd."

Gawker staff members did not think outside the box either. As many as 15 had exceptionally weak passwords. One staffer had his password set to his name, followed by "1." Many others simply used common phrases and words.

Source: PC World

Posted in

Comments

Re: Password Insecurity: An Analysis of Gawker User ...

When people come to ask me how to hack someone else orkut, MSN, etc... (when you are the tech savy guy this is the only reason people call you, beside broken computers), I have to explain that it is actually near impossible, and what happen is that those that claim got their account "hacked" or gave their passwords, or had a stupid password.

 

And I learned about stupid passwords the hard way, someone logged in on my ICQ (54413174) about 3 yeras ago, and changed the password :/ I never got it back. (the password was 1234... I kinda deserved it).

 

--- Maurício Gomes twitter.com/agfgames

--- MaurĂ­cio Gomes twitter.com/agfgames

Re: Password Insecurity: An Analysis of Gawker User ...

Glad I don't use Gawker

Re: Password Insecurity: An Analysis of Gawker User ...

Luckily, I checked and my data was not part of the list.

 

Yay for me?

-------------------- Making sure I retain my INSANITY
Forgot your password?
Username :
Password :

Shout box

You're not permitted to post shouts.
tallimarhttp://news.cnet.com/8301-1035_3-57440902-94/microsoft-legal-win-over-google-may-signal-ceasefire/05/24/2012 - 10:17pm
ZippyDSMleeTIme or an operation!05/24/2012 - 6:43pm
ZippyDSMleePC parts are in wish me luck or hell!!05/24/2012 - 6:43pm
MaskedPixelante38 Studios and Big Huge Games are pretty much dead now. http://www.joystiq.com/2012/05/24/38-studios-and-big-huge-games-lay-off-entire-staffs05/24/2012 - 4:39pm
DorthLousActually, nop, I did miss the emoticon for some reason (getting used to pics?) and I didn't know you changed it since (since I posted previous to my shout and it was still there.) Anyhow, thanks for taking it out!05/23/2012 - 6:01pm
james_fudgeWell we were just testing it. but it is still on the submission to fight $pam.05/23/2012 - 5:48pm
E. Zachary KnightJames, No I don't have it. I was just wondering who does and why. More curiosity than anything.05/23/2012 - 5:38pm
james_fudgeDid you not see the emoticon and did you not see that it has already been changed back?05/23/2012 - 5:10pm
james_fudgeLOL05/23/2012 - 5:07pm
DorthLousWhy? Not shocked that people are barking to an additional hoop to jump through when posting from their already logged in account or just mentionning this to try to paint me as one always complaining?05/23/2012 - 4:45pm
james_fudgebig shock there ;)05/23/2012 - 4:30pm
DorthLousI'll add my voice to those wanting it gone :S I'm already logged in, I don't need a captch'a. That's for those registering.05/23/2012 - 3:54pm
james_fudgeEt tu EZK?!?05/23/2012 - 3:51pm
Craig R.I'm a One Man Quorum! And it's working for me now, thanks. :)05/23/2012 - 3:48pm
E. Zachary KnightHow do we determine who get's the game/captcha thingy? Is there a certain posting threshhold users have to meet before it is turned off?05/23/2012 - 2:25pm
james_fudgeGive it a chance, we're still adjusting it ;)05/23/2012 - 11:20am
james_fudgeOne does not a Quorum make Craig.05/23/2012 - 11:16am
Craig R.If I complete the stupid game, and it just deletes my comment, what's the point?05/23/2012 - 11:15am
Craig R.Ok, the little captcha game? You can get rid of it already.05/23/2012 - 11:13am
Craig R.FCC boss is giving the thumbs up to usage-based pricing for Internet access05/23/2012 - 11:08am

Be Heard - Contact Your Politician