Americans keep using terrible passwords in 2026 as survey finds pet names and birthdays still rule

https://fed.brid.gy/r/https://nerds.xyz/2026/01/americans-bad-password-habits-2026/

#PasswordReuse is rampant: nearly half of observed user #logins are compromised
Many users recycle #passwords, creating a ripple effect of risk when #credentials are leaked.
Based on Cloudflare's observed traffic between Sep-Nov 2024, 41% of successful logins across websites protected by Cloudflare involve compromised passwords.
When including bots 52% of all authentication requests contain leaked passwords found in our 15B record database, including Have I Been Pwned.
https://blog.cloudflare.com/password-reuse-rampant-half-user-logins-compromised/
Password reuse is rampant: nearly half of observed user logins are compromised

Nearly half of observed login attempts across websites protected by Cloudflare involved leaked credentials. The pervasive issue of password reuse is enabling automated bot attacks and account takeovers on a massive scale.

The Cloudflare Blog

Once again, I’m finishing this Sunday feature from Dulles Airport. Tonight’s destination is London, courtesy of a press trip Uber is hosting for the Go-Get Zero event it’s staging there to talk about its vehicle-electrification ambitions. (My editors at PCMag approved this arrangement, and I’ll note the comped-travel part of it in the copy I file.)

This was a slow week for me in terms of published stories, but Patreon readers got one more post by me: a review of disinformation researcher Renée DiResta’s book Invisible Rulers: The People Who Turn Lies Into Reality. It’s well worth reading if you, too, had some side-eye reactions to the moment in the vice-presidential debate when Republican candidate Sen. JD Vance (R-Ohio) answered a question from Democratic candidate Gov. Tim Walz (D-Minn.) about whether Trump lost the 2020 election by pivoting to a complaint about Facebook content moderation.

10/2/2024: Not Great: Even Password Manager Subscribers Reuse Passwords, PCMag

Usually, Dashlane’s PR folks not only offer advance access to their studies on an embargoed basis but remind me of that multiple times. For whatever reason, that didn’t happen with this particularly interesting study, which I appreciated because it relieved me of any time pressure to have a writeup ready to go before the company posted the study. Instead, I could spend several hours in a back-and-forth e-mail conversation with some Dashlane publicists to make sure that I understood how they did this research. And to ask what thoughts they had after seeing so many users of their own service fail to heed one of its most basic bits of security advice.

(Okay, I also probably would have filed this faster if I hadn’t spent the day on a telecom spectrum-policy conference that occupied most of my attention.)

https://robpegoraro.com/2024/10/06/weekly-output-password-reuse-by-password-manager-users/

#Dashlane #passwordHygiene #passwordManager #passwordReuse

Uber on Instagram: "Join us live 🎙️ from London for GO-GET Zero as we share how Uber is helping to make more sustainable choices the easy choice for everyone. 🍃♻️💚🌱 #GoGetZero #OnOurWay   ✅ October 8 ✅ Live on Uber’s YouTube channel ✅ 10 AM GMT"

253 likes, 102 comments - uber on September 30, 2024: "Join us live 🎙️ from London for GO-GET Zero as we share how Uber is helping to make more sustainable choices the easy choice for everyone. 🍃♻️💚🌱 #GoGetZero #OnOurWay   ✅ October 8 ✅ Live on Uber’s YouTube channel ✅ 10 AM GMT".

Instagram

#23andMe data #breach: Hackers stole raw #genotype data, #health reports
The #credentials used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms. https://www.bleepingcomputer.com/news/security/23andme-data-breach-hackers-stole-raw-genotype-data-health-reports/

Please get a #passwordmanager like #bitwarden. And please for the of all that is holy so #passwordreuse

23andMe data breach: Hackers stole raw genotype data, health reports

Genetic testing provider 23andMe confirmed that hackers stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27.

BleepingComputer

@WorfEmail

Well if they haven't before, I guarantee they will after. Mass password changes are the best time for hackers to gain access to systems. Not just the potentially compromised one, but all across people's tech footprint as people struggle to find a "new" password that they can remember.

#PasswordReuse #SlightlyDifferent

I mean, not bad for a Facebook meme addressing #PasswordReuse

How a bad password policy at Bank of America reduces security

When you force people to use hard-to-remember passwords, you're actually forcing them to use bad passwords.

https://blog.kamens.us/2023/06/09/how-a-bad-password-policy-at-bank-of-america-reduces-security/

#ComputerSecurity #Computers #ConsumerActivism #Internet #UserExperience #Web #BankOfAmerica #BoA #InformationSecurity #infosec #PasswordReuse #PasswordSecurity #passwords

How a bad password policy at Bank of America reduces security

When you force people to use hard-to-remember passwords, you’re actually forcing them to use bad passwords.

Something better to do

As folks hunt for available #mastodon instances–with many now having closed their signups–it’s particularly important to use a unique password.

I haven’t heard of any malicious servers yet, but anyone can set up and promote an instance, so don’t give the potentially unknown person running yours the same password you use for your email and bank accounts!

#infosec #security #passwordreuse

https://xkcd.com/792/

Password Reuse

xkcd

MFW I realize we're basically now living in #xkcd792 but with competently evil Black Hats.

https://xkcd.com/792/

#xkcd #PasswordReuse #power

Password Reuse

xkcd

RT RachelTobac

To reach the ~youth~ we're going to have to make infosec sea shanties, aren't we? Guess so!
Behold the tale of kid who reuses their passwords & ends up pwn'd, then learns how to stay safe. We're on a mission to encourage unique passwords stored in a password manager with MFA on.

https://twitter.com/RachelTobac/status/1352409636792492035

#InfoSec #SeaShanty #Shanty #SeaShanties #Shanties #TheWellerman #Password #Security #2FA #PasswordReuse #PWN

Rachel Tobac on Twitter

“To reach the ~youth~ we're going to have to make infosec sea shanties, aren't we? Guess so! Behold the tale of kid who reuses their passwords & ends up pwn'd, then learns how to stay safe. We're on a mission to encourage unique passwords stored in a password manager with MFA on. https://t.co/QDL9cjUOiC”

Twitter