Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service).

Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.




This isn't a comprehensive list of all leaked passwords. It's a random subset of 10 million for research purposes.


I don't think it is necessary to have one password for every single system, but three or fours tiers of passwords.

And just keep in mind that there's one password to "rule them all". That is the password for the primary mail account. I use 2-factor authentication for that.


> three or fours tiers of passwords

Can you elaborate? My first thought is tiered by category of the service. No, I don't want my financial institutions to all have the same password, even if it's from the most secure tier.


Sites require you to sign up but it won't matter much if someone gains access to your account on them. Those might as well share a password. Same with sites that share trust buckets like [goodreads, yelp], [facebook, twitter] etc.

In the real world though just memorize separate bank and email passes and use a password manager w/generated passwords for everything else.


This is 10 million out of 1 billion that he has.

So there is only a 1% chance of a leaked account getting in this list.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: