F
19

Can we talk about why everyone still uses "password123" in 2024?

I checked my company's leaked credentials on haveibeenpwned last week and 14 out of 40 accounts still had the same password from 2019. Two of those were managers who got phishing training twice. What's the point of all those security webinars if nobody actually changes their habits?
2 comments

Log in to join the discussion

Log In
2 Comments
evahenderson
Training fatigue is real, but honestly, forcing everyone to change a password every 90 days just makes people pick garbage like "Password6!" with a new number. Makes more sense to let people stick with a strong one they actually remember than to keep cycling bad habits.
1
ivan_murphy80
@evahenderson yeah "Password6!" is a perfect example lol. It reminds me though, NIST actually updated their guidelines a while back to say periodic changes aren't needed unless there's a breach, so you're spot on about the old 90 day rule being outdated.
2