How come it’s nonetheless potential to ‘safe’ a web-based account with a six-digit string?
07 Could 2026
•
,
4 min. learn

The most-used password globally is strictly what you suppose it’s: ‘123456.’ That’s in accordance with NordPass’s newest annual report on passwords uncovered in knowledge breaches globally. Different all-too-predictable decisions, resembling ‘123456789’, ‘12345678’, ‘12345’ and ‘admin’, additionally show to have endurance 12 months after 12 months.
My first intuition is to dismiss this as scaremongering fodder, particularly provided that poor password hygiene was additionally a part of a group engagement session I offered on the current RSAC convention, Let’s Rant: 4 Issues That Have to Change in Cybersecurity.
However since immediately is World Password Day, I needed to put this to the check: Can I nonetheless discover a moderately mainstream web site that permits me to create an account utilizing ‘123456’ because the password? Sadly, the reply is sure.
There are fashionable websites, resembling ‘evite’, that also enable this actual six-digit string for use as a password. You might dismiss it as simply an e-invite service, till you understand that you simply’re sharing private knowledge in your invites and probably handle the responses of all of your invitees via an account that isn’t safe. The stunning a part of this very crude check is the discovering that Evite was topic to a knowledge breach in 2019 that affected the private data of over 100 million folks. The corporate ought to most likely know higher than to permit its customers to have such weak passwords.
The scenario isn’t drastically higher on much more fashionable providers. Once I tried to create a brand new account on Fb, the platform did mandate a further stage of password complexity. However nonetheless, a string so simple as ‘1234567!’ turned out to be a permitted password. X provided an analogous expertise.
Now, Fb, for instance, does supply some recommendation, resembling: “keep away from utilizing widespread phrases resembling ‘password’’ and “In case your password isn’t sturdy sufficient, combine uppercase and lowercase letters. Make it extra advanced through the use of an extended phrase or sequence of phrases that you would be able to bear in mind however others received’t know.” But, it permits ‘1234567!’ for use, no letters, only a sequential sample with a easy exclamation mark on the finish, all simply guessable, particularly by automated scripts that check accounts en masse for generally used patterns and strings.
In the meantime, Collins Dictionary, which is dwelling to far much less delicate content material, pressured me to create an eight-character password containing at the least three of the next – decrease case (a-z), higher case (A-Z), numbers (i.e. 0-9) and particular characters (e.g. !@#$%^&*).
NordPass’s knowledge means that there are numerous extra websites that set restricted password insurance policies and permit trivial passwords like ‘123456’. Nevertheless, I believe there may be parts of legacy within the methodology used to calculate the commonest passwords. For instance, if an organization has existed for 10 years and by no means deleted any dormant person accounts, then a breach would come with outdated dormant account data, a few of which can be from earlier than any password coverage was enforced. The motivation behind publishing headline-snatching knowledge can also be clear: the distributors that create the information story are set to probably profit as they supply password administration software program for a subscription.
Breaking the cycle
Now, how will we resolve this unending loop of negativity about passwords, together with the ridiculous scenario that platforms nonetheless allow non-secure passwords?
I don’t help the concept of legislators needing to mollycoddle residents, however on this occasion I believe it’s time for lawmakers to step on top of things and put a cease to the sample of firms not implementing stringent authentication insurance policies and permitting shoppers to take the straightforward possibility. There may be widespread privateness laws stating that firms have to safe our private knowledge in the event that they retailer it, utilizing applicable cheap cybersecurity measures. A core a part of these measures is using sturdy, advanced passwords and multi-factor authentication (MFA), as required by any self-respecting cybersecurity framework. But, in lots of situations there aren’t any cybersecurity necessities on authentication for customer-facing providers.
However, some industries have been pressured to replace to fashionable authentication strategies. Within the finance business, for instance, there are a number of laws, such because the Cost Providers Directive 2 (PSD2), that mandate MFA for digital funds and entry to fee accounts on-line.
Laws ought to lengthen to all industries: merely implement MFA for all accounts created on-line whatever the service being accessed, ditch the outdated use of passwords, and transfer to extra applicable safety for immediately’s web.
The potential hurdle to mandating this strategy is the barrier to entry for folks creating accounts. Firms reliant on promoting or the gathering (and sale) of private knowledge for income will foyer considerably in opposition to the transfer, and firms with massive budgets shall be very demanding that nothing steps in the way in which of revenue, particularly one thing like securing buyer accounts by requiring a fancy password and/or MFA.
For many of my 30-plus-year profession within the cybersecurity business, the problem of weak passwords has been a staple message pushed out each day, at many occasions, and on a specifically nominated day. There’s a easy and efficient solution to resolve it: mandate advanced passwords or, higher but, MFA. Can we please cease the dialog about ‘weak passwords’, as soon as and for all?
To generate sturdy passwords and be taught extra about on-line account safety, head over to ESET’s password generator web page.

