
NordPass, the password manager brand of the Nord Security group, has released the findings of its sixth common passwords report covering 44 countries, including Australia. The data comprises personal and corporate passwords that were part of known data breaches or stolen by malware, but company claims no personal data was acquired as part of the study.
NordPass estimates almost all of the most-common passwords in the study take less than one second to crack.
By far, the most common passwords for Australians are the almost satirical “password”. “Qwerty123”, “123456”, and “qwerty1”. Of course, the old standard “password1” makes a showing, but only as the 8th most used (it still takes less than one second to break). But there were a few that bucked the trend, including "lizottes", "pokemon", "dragon", and "charlie".
Here’s the full top 20 list from Australia and the world:
| Rank | Password | Time to crack | Count |
|---|---|---|---|
| 1 | password | Under 1 second | 12,449 |
| 2 | qwerty123 | Under 1 second | 11,979 |
| 3 | 123456 | Under 1 second | 11,389 |
| 4 | qwerty1 | Under 1 second | 11,282 |
| 5 | 123456789 | Under 1 second | 4,233 |
| 6 | lizottes | 3 hours | 4,015 |
| 7 | qwerty | Under 1 second | 3,401 |
| 8 | password1 | Under 1 second | 2,780 |
| 9 | 12345678 | Under 1 second | 2,412 |
| 10 | Abcd1234 | Under 1 second | 2,332 |
| 11 | abc123 | Under 1 second | 2,252 |
| 12 | Password1 | Under 1 second | 2,081 |
| 13 | Password | Under 1 second | 2,058 |
| 14 | guest | 10 seconds | 1,944 |
| 15 | 12345 | Under 1 second | 1,801 |
| 16 | pokemon | Under 1 second | 1,411 |
| 17 | Qwerty123 | Under 1 second | 1,361 |
| 18 | dragon | Under 1 second | 1,331 |
| 19 | 1234567890 | Under 1 second | 1,323 |
| 20 | charlie | Under 1 second | 1,294 |
| Rank | Password | Time to crack | Count |
|---|---|---|---|
| 1 | 123456 | Under 1 second | 3,018,050 |
| 2 | 123456789 | Under 1 second | 1,625,135 |
| 3 | 12345678 | Under 1 second | 884,740 |
| 4 | password | Under 1 second | 692,151 |
| 5 | qwerty123 | Under 1 second | 642,638 |
| 6 | qwerty1 | Under 1 second | 583,630 |
| 7 | 111111 | Under 1 second | 459,730 |
| 8 | 12345 | Under 1 second | 395,573 |
| 9 | secret | Under 1 second | 363,491 |
| 10 | 123123 | Under 1 second | 351,576 |
| 11 | 1234567890 | Under 1 second | 324,349 |
| 12 | 1234567 | Under 1 second | 307,719 |
| 13 | 000000 | Under 1 second | 250,043 |
| 14 | qwerty | Under 1 second | 244,879 |
| 15 | abc123 | Under 1 second | 217,230 |
| 16 | password1 | Under 1 second | 211,932 |
| 17 | iloveyou | Under 1 second | 197,880 |
| 18 | 11111111 | Under 1 second | 195,237 |
| 19 | dragon | Under 1 second | 144,670 |
| 20 | monkey | Under 1 second | 139,150 |
Good password practice isn’t as hard as it sounds
Even if your password isn’t on the top 20 list, that doesn’t mean you’re in the clear. And even if it would take a while for an automated program to crack, that doesn’t necessarily make it strong.
Lets look at some of the ultra basic dos and don’ts when it comes to your passwords, how to come up with unique password ideas, and we’ll cover some of the easier ways you can build and maintain better habits.
We'll cover password managers first, but also cover the basics if adding an extra paid subscription doesn't sound like your cup of tea.
Password managers are easy and safer
A password manager can create, remember and input your passwords for you. This means you can have detailed and unique passwords for every account, but your fallible human brain only has to remember the password for your password manager.
Many have options for monthly or annual billing. In these cases the annual price is almost always significantly cheaper, but it at least means you can try one out for a month or two to see if you like the experience. Some also have a free subscription tier, though these are usually restrictive and might end up being more frustrating than helpful.
Here's a quick look at what you might expect to spend for some of the better-known brands:
Make sure whichever one you sign up to has well-reviewed downloadable applications for all your devices – be they Android, Windows, macOS, iOS, iPadOS or Linux. It can be frustrating if you're limited to a browser-only experience.
Speaking of which, it's rare to find one that doesn't have a browser extension (also crucial), but it's best to check.
Use strong passwords
Obviously, you should avoid the common passwords in the report, but there are some simple tricks you can keep in mind for creating strong passwords.
Don’t use single words
Single words, particularly dictionary words or common names, are extremely breakable for automated programs. A computer can run through the entire dictionary in moments, including any not-so-clever derivations like adding a number or symbol to the end.
The term “pass phrase” is sometimes used to communicate this, but even that’s problematic because it suggests your words should somehow be related. Instead, choose at least two words that have nothing to do with each other, e.g. "potatocow".
Use acronyms
While a grammatically correct pass phrase isn’t necessarily the best choice, turning a memorable and unique string of words into an acronym can create the foundation for extremely strong passwords. For example, “I love dogs and especially my fluffy boy, Kevin” gives you “ildaemfbk” to work with. But avoid common sayings and don’t repeat the same string of letters.
Use random capitalisation
You’re usually required to use a capital letter in a password, but capitalising the first letter is almost pointless. An extremely easy way to up your password strength is to capitalise any letter but the first or last. If you want to make it easier to remember, pick a number and stick to it – e.g. always capitalise the fifth letter. But it’s best to add multiple capitals and keep things random.
Randomly insert symbols
Don’t put your symbol or number at the start or end. As with random capitalisation, put your symbols within the password, rather than on either end. This should make them much harder to crack via automation.
Don’t re-use passwords or PINs
You’ll have heard this time and again, but it’s still one of the most common blunders people make. You likely use the same email login for multiple services, including crucial ones such as banking, medicare, the ATO, and more. If your password gets cracked anywhere, hackers can take those login details and use them to access anywhere else you’ve used them.
This is particularly dangerous if you use the same password on smaller websites as you do for your important accounts. For example, a small retailer will likely have worse safeguards than your bank. But all a hacker needs to do is breach the retailer’s defenses to grab your re-used password.
Don’t use personal details
Brute-force hacking from an automated program isn’t the only threat. “Social hacking” is a common tactic that relies on publicly available information about you, including important dates, family members, pets, etc.
Don’t post personal details
Whether maliciously or not, many online accounts publish posts like “What was your high school and what did you hate about it?” or “What was your first car and how much did it cost?”
If you spotted these have an alarming similarity to the “secret questions” some services still use to this day to authenticate your identity when you hit “forgot password”, you’ve done better than the hundreds of people who comment on such posts.
You should also hit up your social media accounts to see if any unnecessary info is in your profile or bio – getting a flood of happy birthday messages on Facebook might be nice, but it’s also personal info that’s commonly used to verify your identity.
If it doesn’t need to be on the web, don’t put it on the web. And if you do, at least set it to Private so that only your friends can see it.
Use 2FA
Two-factor authentication (2FA) is a huge security upgrade for any online account because it requires more than just your password.
It normally relies on an always-changing number in a linked authentication app or a code sent to your SMS or email. The former is preferable, but sometimes it's not an option. Use 2FA wherever possible, especially for your most sensitive accounts.
Beware phishing scams
Phishing is a type of scam that involves tricking you into giving up either personal info or login details. This type of scam can be extremely sophisticated and fool even the most security-conscious among us, but you should still always keep it in mind.
Phishing can be done via email, text, online messaging, phone, or pretty much any communication medium, including turning up at your door (though that last one is pretty rare). Even worse, given the increasing power of AI, it can be automated, allowing scammers to contact exponentially more people than it would take to do manually.
For example, you might receive an email from “myGov” informing you of an issue like an unpaid tax debt, along with a link where you need to fill out your details and “sign into myGov”. The page you’re sent to could look like a perfect copy of a normal myGov login page, and the email might be from an innocuous address like “[email protected]” (myGov generally uses “@my.gov.au”).
Once you enter your login details, banking details, personal info or whatever else, the scammers now have it.
So, how do you tell? First, never click a link that asks you to input your login details or hand over personal info. Always look the company, department or organisation up separately and find the login that way. The same goes for giving out your details over direct messaging or phone – end the conversation (politely) and call the company back via its publicly available customer service channels.
As for those cloned websites, you can’t clone a website address perfectly. E.g. something like “mygove.net” is very much not the official website: “my.gov.au”. Once again, finding the website via a web search is usually a safe bet.
These are currently the most popular NBN 50 plans in our database of 34 internet providers:
Alex Angove-Plumb
Digital Content Editor
Related Articles
Internet Plans by State
- Internet Plans in ACT
- Internet Plans in NSW
- Internet Plans in NT
- Internet Plans in QLD
- Internet Plans in SA
- Internet Plans in TAS
- Internet Plans in VIC
- Internet Plans in WA