A few days ago we posted a story highlighting reports that tens of thousands of Hotmail passwords had been leaked onto public text sharing websites. By now, many people would have accessed and used the stolen data but one security researcher by the name of Bogdan Calin decided to analyse the usernames and passwords. His report came up with some very surprising (or in some cases unsurprising) results:
- The longest password was found to be 30 characters long: lafaroleratropezoooooooooooooo
- The shortest password being just a single character: )
- The most popular password was: 123456, used by at least 64 people found on the list.
- The average password length was 8 characters, with 42% of all passwords consisting of lower alpha characters.
Bogdan made the assumption that the compromised data was extracted using various phishing techniques, most likely a dummy webpage that looked and acted like an official Windows Live Mail login screen. It is also likely that this attack was aimed at the Latino community from looking at the 20 most common passwords:
- 123456
- 123456789
- alejandra
- 111111
- alberto
- tequiero
- alejandro
- 12345678
- 1234567
- estrella
- iloveyou
- daniel
- 000000
- roberto
- 654321
- bonita
- sebastian
- beatriz
- mariposa
- america
Of course when there are security scares such as this it is advisable to change your password, making sure to use both uppercase and lowercase letters, numbers and even special characters. A simple Google search for “password generator” will give you a decent list of websites from which you can generate a strong and safe password.















Many Spanish words!
There are TWO major flaws here:
1. Hotmail/Live mail doesn’t allow you to use a single character password!
2. The max hotmail password length is about 20 chars. So you cannot use a password of 30 chars.
In fact there is a 6 char minimum for all passwords. It’s possible the data is as a result of people entering in incorrect data which was added to the phishing list regardless.
I’m surprised passwords such as “qwerty” and “password” aren’t on the top 20!
Until some years ago minimum was 4 characters. I still have a 4 characters long password on my hotmail account.