Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This guy only used 302 from a dump of 453,491 passwords to come to these conclusions. I can imagine no reason why he'd intentionally invalidate his analysis by using such a low sample size unless this conclusion doesn't actually hold when you use a significant sample. I am highly skeptical.


I read it differently:

  "This is from a sample size of 302 common accounts and
   unsurprisingly, the strength of those passwords leaves
   a lot to be desired:"
The word "this" refers to the passwords list after the colon, not the preceding analysis. It really should have been written as "The following list of weak passwords is from a sample size of 302...".


The emphasis should have been on "common" - there were only 302 emails out of the full sample which appeared in both breaches. I would have like a larger sample size, but that's all there was.


Ah, my mistake. Thanks for clarifying!




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: