3 ms·
Who knows? All I am doing is working from the data available. I've tried to be clear about the methodology. My guess is that most users just reuse a small numb
by xlfe 13y ago
Who knows? All I am doing is working from the data available.
I've tried to be clear about the methodology. My guess is that most users just reuse a small number of passwords. Anecdotal evidence supports this.
If you have a suggestion for how to derive a better _estimate_ from available data I'd be very interested to hear it.
- Peaker 13y agoYou're looking under the flashlight. A better analysis could be done if it were compared with another password leak from another site. But even if there's no better analysis, the best analysis may still be severely broken.
- xlfe 13y agoThanks for the feedback. I think it's debatable actually - while intersecting the list with another does give you less bias, it also reduces the sample size immensely (as happened in the 2011 analysis I linked to), so there are trade offs in both directions. I'm not claiming that I know exactly how many accounts reuse passwords - I am suggesting that, based on my estimate, it is more than half. The evidence (that I've linked to) supports this. There are other studies which show upto 60% of password reuse: http://www.troyhunt.com/2012/07/what-do-sony-and-yahoo-have-in-common.html http://www.troyhunt.com/2012/07/what-do-sony-and-yahoo-have-... If you can produce a better estimate please go ahead.
- Peaker 13y agoI don't doubt there is much password reuse. Like the original complaint, I don't think the data point has value because reusing passwords on same site implies nothing on different sites.
- thatthatis 13y agoSince your lower bound ignores a common case: I use a formula based on the site to create a [unique]+[common] combined password, your premise that it is a lower bound is invalidated. A better lower bound would be: find password hashes that occur with high frequency. "password1" and "wordpass" are probably each in the data a few thousand times (or rather their hash is in there a few thousand times). Then use the logic that if a person is using an extremely common, known insecure password, that they're probably using the same lazy password in a lot of places. Use this as a lower bound, as it is a lot more defensible.