New Issue: Orbital Catastrophe Ahead? Read Now

Star Wars Terms among 2015's Worst Passwords

In general, people tend to use passwords that are so common and easily guessable as to be nearly worthless in practice

Yuri_Arcurs ©iStock.com

Join Our Community of Science Lovers!

One would think that, after years of exhortations, most people would know better than to use “password” or “12345” to protect their most sensitive data. Evidence suggests, however, that bad passwords are as popular now as they ever were, and the top 25 are trivially easy to guess.

An annual study has exposed 2015’s worst passwords, and if you’re using any of them for your accounts, now is as good a time as any to change it to something a little harder to guess.

Every January, SplashData, a Los Gatos, California-based password-management company, produces a study of the previous year’s worst passwords. The company does not share its methodology unless you sift through a (free) eBook that it sends via e-mail, but the basics are easy enough to understand. The company shares 25 passwords that are so common and easily guessable as to be nearly worthless in practice.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


If you read our previous reports, you won’t be shocked that “123456” is still the most common dumb password, with “password” still occupying the No. 2 spot. The rest of the top 10 were similarly eye-rolling: “12345678,” “qwerty,” “12345,” “123456789,” “football,” “1234,” “1234567” and “baseball,” in that order. Suffice to say, don’t use a linear string of numbers to protect your most sensitive data.

Other offenders from further down the list were equally uninspired, from “welcome” at 11, to “abc123” at 13, to “letmein” at 19 (a perennial favorite since the early days of the Interwebs). Of more interest were some of the new entries, including “welcome,” “login” and “1qaz2wsx.” (The last one may seem clever until you realize that it’s just the first two rows of keys tapped vertically.)

SplashData also drew attention to three relatively new entries: “princess,” “solo” and “starwars.” These passwords, seemingly inspired by a galaxy far, far away, may or may not persist on the list, since the popularity of Star Wars tends to wax and wane with film releases. Even so, it’s probably safer to avoid simple Star Wars passwords for the moment. (Nowhere did “captainkirk1701” show up on the list, once again proving that the Star Trek franchise is superior.)

In case you’ve been silly enough to use one of the passwords on the list, SplashData does have a few commonsense recommendations: a password should be at least 12 characters long, and use a mix of numbers and upper- and lower-case letters. Don’t use the same password for multiple sites, and if you have a ton of passwords, use a password manager to keep them straight.

SplashData recommends its own password-management program, SplashID, but there are plenty of other good ones on the market.

Copyright 2016 Toms Guide, a Purch company. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

Subscribe to Support Independent Journalism

Great science journalism requires human expertise, time, effort and creativity. And it costs money. That’s why I and the journalists here at Scientific American hope you’ll join our community.

When you subscribe, you are supporting staff and freelance journalists who are passionate about telling science stories that are true, important and compelling. Our editors and reporters are often experts in their fields, which means they understand the nuances of big discoveries and can untangle the breakthroughs from the hype. With a subscription, you are also supporting rigorous fact-checking to ensure the words we publish are precise and accurate. And you’re supporting original illustrations, graphics and photos that bring you closer to an advanced laboratory, an ice sheet in Antarctica or a space mission in orbit. You’re helping us craft other types of high-quality journalism as well: Our newsletters are carefully written, edited and curated by staffers you have or will come to know and love. Our Science Quickly podcast is based on original reporting, collaboration with editors and scientists and exacting production.

Subscriptions keep this engine running so we can continue to deliver thoughtful, rigorous and independent science journalism to you. In an era of viral misinformation, this work is crucial. If you value what we do, I hope you’ll consider joining us as a subscriber

Thank you,

Jeanna Bryner, Editor in Chief, Scientific American

Subscribe