MySpace users have stronger passwords than corporate users

Bruce Schneier analyzes the data from a successful phishing attack on MySpace and compares the captured user-passwords to an earlier data-set from a corporation and concludes that MySpace users are better at coming up with good passwords than corporate drones. The article is a great state-of-the-password address, with lots of fun nuggets like "We used to quip that 'password' is the most common password. Now it's 'password1.' Who said users haven't learned anything about security?"

While 65 percent of passwords contain eight characters or less, 17 percent are made up of six characters or less. The average password is eight characters long.

Specifically, the length distribution looks like this.

Yes, there's a 32-character password: "1ancheste 23nite41ancheste 23nite4." Other long passwords are "fool2think fool2thinkol 2think" and "dokitty17darling7g7darling7."

Link