"password"
Names of close people - user, siblings, parents, boyfriend/girlfriend, husband/wife, children, pets - "Johnny"
Name + birth year of user or close people - "Johnny2002"
Name + significant date (e.g., anniversary) - "Johnny15082010"
Name + lucky number - "johnny7"
Street name - "Sepulveda"
Favorite place - "Disneyland"
"I love" + favorite place or favorite food or favorite activity or favorite person - "IloveBeyonce"
Consecutive keys on the keyboard - "asdfgh"
Consecutive numbers - "12345"
Consecutive letters of the alphabet - "abcdef"
Why do users make these choices: assume a human will try to guess their password by manually trying different strings and will get bored before they guess correctly
What really happens: attackers automate guessing using large dictionaries and exploring many word combinations, millions of guesses per second
How do attackers make millions of guesses and don't get locked out for wrong guesses? Think of some possible answers to this question, then click the button to find out the answer.