# Ashley Madison subscribers choose Rotten Passwords

**URL:** <https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [August 27, 2015, 3:13pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071 "2015-08-27T15:13:34Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![CalMeacham](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/calmeacham/32/35_2.png) [@CalMeacham](https://boards.straightdope.com/u/CalMeacham)\
**Post date:** [August 27, 2015, 3:13pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/1 "2015-08-27T15:13:34Z")

</div>

I suppose we should expect this, since we know how bad people are at choosing passwords, but you’d think that on a site dedicated to indiscretions people would be a little more careful.

These choices of passwords could turn out to be the most embarrassing thing we learn about Ashley Madisonizens, even more than their marital infidelities:

> [@](#):
>
> When hackers swiped an estimated 36 million accounts associated with [AshleyMadison.com](http://AshleyMadison.com), a site which helps married people cheat on their partners, there was a rush to find out what had been stolen.  
> …  
> The most common password was “123456,” which scores a zero on the imagination scale, while, perhaps worse, “password” ranked in second place. (You can download the full list from Google Drive, where Pierce uploaded the data.)
> 
> In comparison to Adobe’s data breach in 2013, which led to the release of 38 million Adobe usernames and passwords, the cracked [AshleyMadison.com](http://AshleyMadison.com) passwords are just as bad. That’s because the most popular password for almost two million Adobe customers was also “123456.” It seems lessons from the past weren’t learned, because when Yahoo suffered a data breach in 2012, the same password, “123456,” was top of the list.

“Ashley” and “Madison” and “qwerty” were also popular (So are, intriguingly, in context, “fuckyou” and “fuckme”), but “123456” heads the list.  
Actually, its not entirely fair to characterize this as I have – these were the passwords that could be broken, and a lot of them haven’t been. So these are really the top “weak” passwords. I’m still surprised people would use them in this context.

> **[This is the worst password from the Ashley Madison hack](https://www.zdnet.com/article/these-are-the-worst-passwords-from-the-ashley-madison-hack/)**
>
> After cracking 4,000 passwords, one decrypted password floated to the top of the list. And it's not for the first time.

---

<div class="post-metadata">

**Author:** ![Morgenstern](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@Morgenstern](https://boards.straightdope.com/u/Morgenstern)\
**Post date:** [August 27, 2015, 3:19pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/2 "2015-08-27T15:19:48Z")

</div>

Wonder where “horney” was on the list.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [August 27, 2015, 3:24pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/3 "2015-08-27T15:24:13Z")

</div>

Probably some ways down from “horny”. Just because people are stupid password-pickers doesn’t mean they all misspell words the same way.

---

<div class="post-metadata">

**Author:** ![Channing\_Idaho\_Banks](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/channing_idaho_banks/32/250_2.png) [@Channing\_Idaho\_Banks](https://boards.straightdope.com/u/Channing_Idaho_Banks)\
**Post date:** [August 27, 2015, 3:44pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/4 "2015-08-27T15:44:23Z")

</div>

> [@LSLGuy](#):
>
> Probably some ways down from “horny”. Just because people are stupid password-pickers doesn’t mean they all misspell words the same way.

Horny is not six characters.

---

<div class="post-metadata">

**Author:** ![TokyoBayer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tokyobayer/32/13989_2.png) [@TokyoBayer](https://boards.straightdope.com/u/TokyoBayer)\
**Post date:** [August 27, 2015, 3:49pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/5 "2015-08-27T15:49:41Z")

</div>

From the quoted article, 123456 was used a mere 202 times out of 36 million accounts. Yawn.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [August 27, 2015, 3:55pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/6 "2015-08-27T15:55:31Z")

</div>

> [@Channing\_Idaho\_Banks](#):
>
> Horny is not six characters.

True. Not being a subscriber I wasn’t aware that was a requirement at that site.

IMO “HornyMe” or variations would be a more plausible choice than “horney”. Unless there area lot of people who really spell it that way. Although I suspect a lot of folks have never had occasion to write that word at all and have no fixed idea of how it is or should be spelled.

---

<div class="post-metadata">

**Author:** ![CalMeacham](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/calmeacham/32/35_2.png) [@CalMeacham](https://boards.straightdope.com/u/CalMeacham)\
**Post date:** [August 27, 2015, 4:11pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/7 "2015-08-27T16:11:17Z")

</div>

> [@TokyoBayer](#):
>
> From the quoted article, 123456 was used a mere 202 times out of 36 million accounts. Yawn.

Well, 202 times out of the 4000 they decrypted. That’s 5%, so it’s not as big a yawn.

---

<div class="post-metadata">

**Author:** ![lazybratsche](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@lazybratsche](https://boards.straightdope.com/u/lazybratsche)\
**Post date:** [August 27, 2015, 4:22pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/8 "2015-08-27T16:22:28Z")

</div>

If I understand it correctly, cracking the passwords is a process involving brute-force guessing for each password. That starts with easy guesses: known common passwords, maybe an exhaustive search of the 6-character password space, dictionary words, and from there longer passwords perhaps focused on common patterns used by most people. They probably found all examples of “123456” and “password” in the entire 36 million passwords.

Luckily for the users here, passwords were properly stored so only the really weak passwords are going to be broken.

---

<div class="post-metadata">

**Author:** ![Morgenstern](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@Morgenstern](https://boards.straightdope.com/u/Morgenstern)\
**Post date:** [August 27, 2015, 6:21pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/9 "2015-08-27T18:21:24Z")

</div>

> [@LSLGuy](#):
>
> True. Not being a subscriber I wasn’t aware that was a requirement at that site.
> 
> …

The first rule of Ashley Madison was what again… Oh yeah. Never admit to… 😉

---

<div class="post-metadata">

**Author:** ![dracoi](https://avatars.discourse-cdn.com/v4/letter/d/90db22/32.png) [@dracoi](https://boards.straightdope.com/u/dracoi)\
**Post date:** [August 27, 2015, 6:56pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/10 "2015-08-27T18:56:16Z")

</div>

who wants to bet that those 202 people used the same 123456 password for their e-mail and bank accounts too?

---

<div class="post-metadata">

**Author:** ![Smapti](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/smapti/32/17938_2.png) [@Smapti](https://boards.straightdope.com/u/Smapti)\
**Post date:** [August 27, 2015, 7:04pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/11 "2015-08-27T19:04:50Z")

</div>

That’s the kind of combination an idiot would put on his luggage!

---

<div class="post-metadata">

**Author:** ![Ethilrist](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ethilrist/32/4604_2.png) [@Ethilrist](https://boards.straightdope.com/u/Ethilrist)\
**Post date:** [August 27, 2015, 7:22pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/12 "2015-08-27T19:22:20Z")

</div>

123456 is a good idea for a password if you’re going to be typing with one hand.

---

<div class="post-metadata">

**Author:** ![Ethilrist](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ethilrist/32/4604_2.png) [@Ethilrist](https://boards.straightdope.com/u/Ethilrist)\
**Post date:** [August 27, 2015, 7:29pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/13 "2015-08-27T19:29:20Z")

</div>

Then again, so is “farted” but it’s a little off, contextually.

---

<div class="post-metadata">

**Author:** ![DrDeth](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@DrDeth](https://boards.straightdope.com/u/DrDeth)\
**Post date:** [August 27, 2015, 8:20pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/14 "2015-08-27T20:20:07Z")

</div>

Apparently there were almost zero real women actually “using” the site. Ashley Madison was a scam.

> **[Almost None of the Women in the Ashley Madison Database Ever Used the Site...](https://gizmodo.com/almost-none-of-the-women-in-the-ashley-madison-database-1725558944)**
>
> When hacker group Impact Team released the Ashley Madison data, they asserted that “thousands” of the women’s profiles were fake. Later, this number got blown up in news stories that asserted “90-95%” of them were fake, though nobody put forth any...

---

<div class="post-metadata">

**Author:** ![Hershele\_Ostropoler](https://avatars.discourse-cdn.com/v4/letter/h/e47c2d/32.png) [@Hershele\_Ostropoler](https://boards.straightdope.com/u/Hershele_Ostropoler)\
**Post date:** [August 31, 2015, 4:51pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/15 "2015-08-31T16:51:25Z")

</div>

> [@CalMeacham](#):
>
> So these are really the top “weak” passwords. I’m still surprised people would use them in this context.

It shows people use these passwords because they don’t understand how weak they are, not because they don’t care whether they’re strong or not.

---

<div class="post-metadata">

**Author:** ![TheSeaOtter](https://avatars.discourse-cdn.com/v4/letter/t/ed655f/32.png) [@TheSeaOtter](https://boards.straightdope.com/u/TheSeaOtter)\
**Post date:** [August 31, 2015, 5:12pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/16 "2015-08-31T17:12:26Z")

</div>

> [@CalMeacham](#):
>
> Well, 202 times out of the 4000 they decrypted. That’s 5%, so it’s not as big a yawn.

According to the blog describing the cracking attempt, they were using the (now famous) RockYou password list. Any password that wasn’t on that (admittedly large) list wasn’t going to get cracked. So it’s 5% of the **bad** passwords.  
**(Edit: Sorry, I missed the post where you pointed out this already.)**

To me, the more interesting thing is that AM was using actual good password storage - salted hashes using bcrypt. Given everything else we’ve learned recently about the company, I was expected unsalted MD5, or maybe plaintext. The rate of 156 guesses per second on a state-of-the-art custom built password cracking machine is really quite slow.

---

<div class="post-metadata">

**Author:** ![Sage\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sage_rat/32/399_2.png) [@Sage\_Rat](https://boards.straightdope.com/u/Sage_Rat)\
**Post date:** [August 31, 2015, 7:43pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/17 "2015-08-31T19:43:19Z")

</div>

> [@CalMeacham](#):
>
> I suppose we should expect this, since we know how bad people are at choosing passwords, but you’d think that on a site dedicated to indiscretions people would be a little more careful.
> 
> These choices of passwords could turn out to be the most embarrassing thing we learn about Ashley Madisonizens

The examples given are the same top passwords on all sites. You would need to look at the percentiles to figure out if the AM crowd were particularly better or worse, on average, than the greater internet.

> [@Smapti](#):
>
> That’s the kind of combination an idiot would put on his luggage!

😃

> [@Ethilrist](#):
>
> 123456 is a good idea for a password if you’re going to be typing with one hand.

Old joke:

What’s the longest word you can type with just your left hand?

Stewardesses

---

<div class="post-metadata">

**Author:** ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)\
**Post date:** [August 31, 2015, 9:06pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/18 "2015-08-31T21:06:32Z")

</div>

> [@TheSeaOtter](#):
>
> To me, the more interesting thing is that AM was using actual good password storage - salted hashes using bcrypt. Given everything else we’ve learned recently about the company, I was expected unsalted MD5, or maybe plaintext. The rate of 156 guesses per second on a state-of-the-art custom built password cracking machine is really quite slow.

That was what I took away, too. They had at least one competent security guy on staff at some point. Basically those passwords are not going be cracked, other than the mind-numbingly simple 123456-esque ones.

It was a really high-end lock they put on that door they didn’t bother to close.

---

<div class="post-metadata">

**Author:** ![Octarine](https://avatars.discourse-cdn.com/v4/letter/o/22d042/32.png) [@Octarine](https://boards.straightdope.com/u/Octarine)\
**Post date:** [September 1, 2015, 12:12am UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/19 "2015-09-01T00:12:46Z")

</div>

123456 is far too obvious - that’s why I use 234567 for all of my important financial accounts. Same ease of typing, but they never guess.

Wait . . .

---

<div class="post-metadata">

**Author:** ![lazybratsche](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@lazybratsche](https://boards.straightdope.com/u/lazybratsche)\
**Post date:** [September 10, 2015, 1:06pm UTC](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071/20 "2015-09-10T13:06:36Z")

</div>

> [@TheSeaOtter](#):
>
> According to the blog describing the cracking attempt, they were using the (now famous) RockYou password list. Any password that wasn’t on that (admittedly large) list wasn’t going to get cracked. So it’s 5% of the **bad** passwords.  
> **(Edit: Sorry, I missed the post where you pointed out this already.)**
> 
> To me, the more interesting thing is that AM was using actual good password storage - salted hashes using bcrypt. Given everything else we’ve learned recently about the company, I was expected unsalted MD5, or maybe plaintext. The rate of 156 guesses per second on a state-of-the-art custom built password cracking machine is really quite slow.

Update:

Turns out [AM used some laughably terrible password security](http://arstechnica.com/security/2015/09/once-seen-as-bulletproof-11-million-ashley-madison-passwords-already-cracked/) after all. While the primary password database used bcrypt to securely hash passwords, the passwords were also stored as MD5 hashes. Even worse, the insecurely hashed version converted uppercase to lowercase, so it was even easier to brute force guess the all-lowercase versions, and trivial to find uppercase characters in bcrypt hashed passwords.

Net result is that all the AM passwords are about a million times easier to crack than previously thought. After ten days of crunching, 11 million passwords have been cracked…

[Next page](https://boards.straightdope.com/t/ashley-madison-subscribers-choose-rotten-passwords/729071.md?page=2)
