Don’t Use This “Random” Password

We live a lot of our lives online. You’re reading these words in your email inbox, you probably logged into a healthcare portal or bank account somewhat recently, and you almost certainly did some online shopping this week. And to get into all of those services, you typically need a password.

That password shouldn’t be guessable — you want something secure that only you’ll know (and maybe a couple of trusted loved ones). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has three simple recommendations: make your passwords long, make them random, and make them unique. So passwords like “password” or “letsgomets” or even “supercalifragilisticexpialidocious” are bad ideas. You’ll want something like “x8Am30fuia0” or “ji32k7au4a83,” right?

Wrong — at least, in the case of ji32k7au4a83.

In 2013, a cybersecurity expert named Tony Hunt launched Have I Been Pwned (that’s not a typo), a website that allows people to see if their online accounts have been compromised in security breaches. One of HIBP’s resources is a database of commonly used passwords. Those are best avoided because hackers often run “dictionary attacks” to gain access to user accounts — an automation tries email addresses and a list of commonly-used passwords, one password at a time, hoping to gain access where they otherwise shouldn’t. If your password matches one commonly found in that HIBP database, you shouldn’t use it. As of this writing, “password” appears about 52 million times, “letsgomets” about 8,800, “supercalifragilisticexpialidocious” about 9,700, and “x8Am30fuia0” doesn’t appear at all. Nothing surprising yet.

But “ji32k7au4a83”? It’s in the database just under 7,500 times.

In 2019, a Twitter user named ArcaneNibble proved his username true when he noticed the discrepancy, asking the following: “the password “ji32k7au4a83” looks like it’d be decently secure, right? But if you check e.g. HIBP, it’s been seen over a hundred times. Challenge: explain why and how this happened and how this password might be guessed.” And others set off to solve the mystery. The answer: it’s Chinese. Kind of.

The phrase “my password” in Mandarin is “我的密碼,” which isn’t something English keyboards can easily type — I had to copy/paste it from here. If you’re in Taiwan, though, you’d not type those characters. You’d probably type out the phonetic equivalent using a different character set, called Bopomofo. On the most common Bopomofo keyboard, the characters would render as “ㄨㄛˇ ㄉㄜ˙ ㄇㄧˋ ㄇㄚˇ” — but don’t worry, you don’t need to know how to read that. Because the databases people are typing that into also can’t read it. Boponmofo keyboards map to the standard keyboards we use in English-speaking nations, and “ㄨㄛˇ ㄉㄜ˙ ㄇㄧˋ ㄇㄚˇ” maps to “ji32k7au4a83.” Taiwanese people speaking Mandarin were typing “my password” when registering for online accounts, but the English-based online accounts were seeing it as “ji32k7au4a83.”

So don’t use that as a password — it’s vulnerable to a dictionary attack And if you had selected that randomly somehow, go buy yourself a lottery ticket, because the odds of doing so are astronomical — about one in 4.74 quintillion.

Bonus fact: You’ll note that, above, CISA doesn’t recommend changing your password often. That’s because it’s probably a bad practice. In 2016, the FTC explicitly began advising against it, noting that “there is a lot of evidence to suggest that users who are required to change their passwords frequently select weaker passwords to begin with, and then change them in predictable ways that attackers can guess easily.”

From the Archives: The Number That’s Illegal to Share: Not a “password” per se but close enough!