Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Nye Bevan

(25,406 posts)
Sat Jan 3, 2015, 02:14 PM Jan 2015

If you are using any of the passwords in this list, change it!

Somebody just uploaded a password-hacking tool called iDict to GitHub that promises to use good old fashioned brute force techniques to crack iCloud passwords. The tool also claims to be able to evade Apple's rate-limiting and two-factor authentication security that's supposed to prevent brute force attacks. But it's not quite as bad as it sounds.

iDict's capabilities are limited by the size of the dictionary it uses to guess your password. So you're really only in danger if your password is on the 500-word-long list included with the hacker tool.

http://gizmodo.com/if-your-icloud-password-is-on-this-list-change-it-befo-1677091364


Here is the list:


!QAZ1qaz ; !QAZ2wsx ; !Qaz2wsx ; !QAZxsw2 ; !QAZzaq1 ; #EDC4rfv ; @WSX2wsx ; 123qweASD ; 12qw!@QW ; 1941.Salembbb.41
1qaz!QAZ ; 1qaz@WSX ; 1qazXSW@ ; 1qazZAQ! ; 2wsx@WSX ; 3edc#EDC ; Aaliyah1 ; ABC123abc ; abc123ABC ; ABCabc123
abcABC123 ; Abcd1234 ; Abigail1 ; Addison1 ; Airforce1 ; Alabama1 ; Alexander1 ; Alexandra1 ; Allison1 ; America1
Anderson1 ; Angel101 ; Angel123 ; Angelina1 ; Annabelle1 ; Anthony1 ; Anthony11 ; Antonio1 ; Arianna1 ; Arsenal1
Arsenal12 ; Arsenal123 ; Ashley12 ; Asshole1 ; Atlanta1 ; August08 ; August10 ; August12 ; August20 ; August22
Austin02 ; Austin316 ; Australia1 ; Awesome1 ; Babyboy1 ; Babygirl1 ; BabyGirl1 ; Babygurl1 ; Bailey12 ; Barcelona1
Baseball1 ; Batista1 ; Beautiful1 ; Beckham7 ; Bella123 ; Benjamin1 ; Bentley1 ; Bethany1 ; Bigdaddy1 ; Blessed1
Blink182 ; Blink-182 ; Blondie1 ; Boricua1 ; Bradley1 ; Brandon1 ; Brandon2 ; Brandon7 ; Braxton1 ; Brayden1
Breanna1 ; Brianna1 ; Brittany1 ; Brittney1 ; Broncos1 ; Brooklyn1 ; Brownie1 ; Bubbles1 ; Buddy123 ; Buttercup1
Butterfly1 ; Butterfly7 ; Buttons1 ; Cameron1 ; Candy123 ; Carolina1 ; Cassandra1 ; Catherine1 ; Celtic1888 ; Chargers1
Charles1 ; Charlie1 ; Charlotte1 ; Charmed1 ; Chelsea1 ; Chelsea123 ; Chester1 ; Cheyenne1 ; Chicago1 ; Chicken1
Chocolate1 ; Chopper1 ; Chris123 ; Christian1 ; Christina1 ; Christine1 ; Christmas1 ; Classof08 ; Clayton1 ; College1
Colombia1 ; Colorado1 ; Computer1 ; Courtney1 ; Cowboys1 ; Cricket1 ; Crystal1 ; Cutiepie1 ; Daisy123 ; Dallas22
Dan1elle ; Daniela1 ; Danielle1 ; David123 ; Death666 ; December1 ; December21 ; Derrick1 ; Destiny1 ; Devil666
Diamond1 ; Diamonds1 ; Dolphin1 ; Dolphins1 ; Dominic1 ; Douglas1 ; Elizabeth1 ; Elizabeth2 ; England1 ; Falcons1
Falcons7 ; Florida1 ; Football1 ; Forever1 ; Forever21 ; Formula1 ; Frankie1 ; Freddie1 ; Freedom1 ; Friday13
Friends1 ; Friends2 ; Fuckoff1 ; Fuckyou1 ; Fuckyou2 ; FuckYou2 ; Gabriel1 ; Gangsta1 ; Garrett1 ; Gateway1
Genesis1 ; Georgia1 ; Gerrard8 ; Giggles1 ; Goddess1 ; Godislove1 ; Gordon24 ; Grandma1 ; Greenday1 ; Harry123
Hawaii50 ; Heather1 ; Hello123 ; Hershey1 ; Holiday1 ; Hollywood1 ; Honey123 ; Houston1 ; Hunter01 ; Iloveme1
Iloveme2 ; Iloveyou1 ; Iloveyou2 ; ILoveYou2 ; Internet1 ; Inuyasha1 ; Ireland1 ; Isabella1 ; Isabelle1 ; Iverson3
iydgTvmujl6f ; Jackson1 ; Jackson5 ; Jamaica1 ; James123 ; January1 ; January29 ; Jasmine1 ; Jazmine1 ; Jeffrey1
Jehovah1 ; Jennifer1 ; Jennifer2 ; Jeremiah1 ; Jessica1 ; Jessica7 ; Jesus123 ; Jesus143 ; Jesus1st ; Jesus4me
Jesus777 ; Jesusis#1 ; Jesusis1 ; John3:16 ; JohnCena1 ; Jonathan1 ; Jordan01 ; Jordan12 ; Jordan23 ; Joshua01
Justice1 ; Justin01 ; Justin11 ; Justin21 ; Justin23 ; Katelyn1 ; Katherine1 ; Kathryn1 ; Katrina1 ; Kendall1
Kennedy1 ; Kenneth1 ; Kimberly1 ; Kristen1 ; Kristin1 ; l6fkiy9oN ; Ladybug1 ; Lakers24 ; Lampard8 ; Laura123
Lebron23 ; Letmein1 ; Liberty1 ; Lindsay1 ; Lindsey1 ; Liverp00l ; Liverpool1 ; Liverpool123 ; Longhorns1 ; Love4ever
Loveyou2 ; Lucky123 ; M1chelle ; Mackenzie1 ; Madison01 ; Madison1 ; Madonna1 ; Makayla1 ; Marie123 ; Marines1
Marissa1 ; Marshall1 ; Matthew1 ; Matthew2 ; Matthew3 ; Maxwell1 ; Melanie1 ; Melissa1 ; Mercedes1 ; Metallica1
Michael01 ; Michael07 ; Michael1 ; Michael2 ; Michael7 ; Micheal1 ; Michele1 ; Michelle1 ; Michelle2 ; Midnight1
Miranda1 ; Molly123 ; Monique1 ; Monkey01 ; Monkey12 ; Monkey13 ; Monkeys1 ; Monster1 ; Montana1 ; Music123
Mustang1 ; Myspace1 ; Natalie1 ; Natasha1 ; Nathan06 ; Newyork1 ; Nicholas1 ; Nichole1 ; Nicole12 ; Nirvana1
November1 ; November11 ; November15 ; November16 ; Nursing1 ; October1 ; October13 ; October22 ; Omarion1 ; Orlando1
P@$$w0rd ; P@55w0rd ; P@ssw0rd ; P4ssword ; Pa$$w0rd ; Pa55w0rd ; Pa55word ; Panther1 ; Panthers1 ; Pass1234
Passion1 ; Passw0rd ; Passw0rd1 ; Password01 ; Password1 ; Password1! ; Password11 ; Password12 ; Password123 ; Password13
Password2 ; Password21 ; Password3 ; Password4 ; Password5 ; Password7 ; Password9 ; Patches1 ; Patricia1 ; Patrick1
Peaches1 ; Peanut01 ; Peanut11 ; Pebbles1 ; Penguin1 ; Phantom1 ; Phoenix1 ; Pickles1 ; Playboy1 ; Pokemon1
Poohbear1 ; PoohBear1 ; Popcorn1 ; Pr1nc3ss ; Pr1ncess ; Precious1 ; Preston1 ; Princess01 ; Princess07 ; Princess08
Princess1 ; Princess12 ; Princess123 ; Princess13 ; Princess15 ; Princess18 ; Princess19 ; Princess2 ; Princess21 ; Princess23
Princess24 ; Princess4 ; Princess5 ; Princess7 ; Prototype1 ; Pumpkin1 ; Qwerty123 ; Raiders1 ; Rainbow1 ; Rangers1
Raymond1 ; Rebecca1 ; Rebelde1 ; Redskins1 ; Ricardo1 ; Richard1 ; Robert01 ; Rockstar1 ; Rocky123 ; RockYou1
Rockyou1 ; Ronaldo7 ; Russell1 ; Rusty123 ; Sabrina1 ; Sail2Boat3 ; Samantha1 ; Santana1 ; Savannah1 ; Scooter1
Scorpio1 ; Scotland1 ; Scrappy1 ; Sebastian1 ; Senior06 ; Senior07 ; September1 ; Serenity1 ; Shannon1 ; Shopping1
Skittles1 ; Slipknot1 ; Smokey01 ; Snickers1 ; Snowball1 ; Soccer11 ; Soccer12 ; Soccer13 ; Soccer14 ; Soccer17
Softball1 ; Spartan117 ; Special1 ; Spencer1 ; Spiderman1 ; Spongebob1 ; Start123 ; Starwars1 ; Steelers1 ; Stephanie1
Stephen1 ; Summer01 ; Summer05 ; Summer06 ; Summer07 ; Summer08 ; Summer99 ; Sunshine1 ; Superman1 ; Superstar1
Sweetie1 ; Sweetpea1 ; Taylor13 ; Tbfkiy9oN ; Teddybear1 ; TheSims2 ; Thirteen13 ; Thumper1 ; Thunder1 ; Tiffany1
Tiger123 ; Tigger01 ; Tigger12 ; Tigger123 ; Timothy1 ; Tinkerbell1 ; Titanic1 ; Trinity1 ; Trinity3 ; Tristan1
Trouble1 ; Trustno1 ; TrustNo1 ; Twilight1 ; Unicorn1 ; Valerie1 ; Vampire1 ; Vanessa1 ; Vanilla1 ; Veronica1
Victoria1 ; Vincent1 ; Welcome1 ; Welcome123 ; Welcome2 ; Whatever1 ; Whitney1 ; William1 ; Winston1 ; Winter06
Yankees1 ; Yankees2 ; z,iyd86I ; Zachary1 ; ZAQ!1qaz ; ZAQ!2wsx ; ZAQ!xsw2 ; zaq1!QAZ ; zaq1@WSX ; zaq1ZAQ!
32 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
If you are using any of the passwords in this list, change it! (Original Post) Nye Bevan Jan 2015 OP
Mine is ******** and it's not on the list. What a relief! Xipe Totec Jan 2015 #1
OMG!!! I just checked and my password is ******** too!!! Thor_MN Jan 2015 #19
Mine are way too weird. cwydro Jan 2015 #2
Mine is ********. bravenak Jan 2015 #3
Amazing Stryder Jan 2015 #4
People actually use Password as their password? Scootaloo Jan 2015 #5
You'd be surprised (and horrified) Posteritatis Jan 2015 #12
Where I work, there is a system account in the Development Environment Thor_MN Jan 2015 #22
Oh, great... IDemo Jan 2015 #6
The combination is 12345. Initech Jan 2015 #7
Sentences = best passwords karadax Jan 2015 #8
I once worked for a company which standardized user passwords Posteritatis Jan 2015 #13
You are correct KentuckyWoman Jan 2015 #16
"This is a sentence" - the new "12345" Scootaloo Jan 2015 #17
Not me, I always use "54321" I've got them fooled! RKP5637 Jan 2015 #18
...Earth below us, drifting, falling | Floating weightless, calling calling home Scootaloo Jan 2015 #20
Yikes! 2naSalit Jan 2015 #24
Oh no! Now I've got "4 3 2 1" stuck in my head!!! RKP5637 Jan 2015 #29
Oh lord Aerows Jan 2015 #31
The other tips I've heard tammywammy Jan 2015 #32
Well, this Princess01 has to reset some passwords. Gormy Cuss Jan 2015 #9
Damn! Most of my passwords are on that list. onehandle Jan 2015 #10
I bet mmonk Jan 2015 #11
Not on the list: Fuckbucket7 NYC_SKP Jan 2015 #14
The access code is...access code. NuclearDem Jan 2015 #15
I've been known to use SheilaT Jan 2015 #21
Mine is Polish katmondoo Jan 2015 #26
Even better. SheilaT Jan 2015 #30
The best password formula I've ever heard of is...... socialist_n_TN Jan 2015 #23
Yeah, I see "Shit4Br@inz51" isn't on there either, whew! 2naSalit Jan 2015 #25
Mine are ten minimum, no repeating characters Aerows Jan 2015 #27
I keep changing mine, mostly because I changed it and forgot the new one... Historic NY Jan 2015 #28
 

Scootaloo

(25,699 posts)
5. People actually use Password as their password?
Sat Jan 3, 2015, 02:21 PM
Jan 2015

I thought that was a computer geek myth, like the CD-rom cupholder

Posteritatis

(18,807 posts)
12. You'd be surprised (and horrified)
Sat Jan 3, 2015, 02:43 PM
Jan 2015

My father's a sysadmin for a medum-large corporation that involves a five-digit number of user accounts, and there was a time early on there where something like five percent of them were "password" (and a good third were similar things - "12345," &quot current month)", &quot dog's name)", &quot kids' birth years)", etc).

Not only are people generally really inept with passwords, but they'll often fight tooth and nail to resist using secure ones. Nothing quite stirs up the info-security despair like overhearing the talk in an office environment when a bunch of passwords expire all at once...

 

Thor_MN

(11,843 posts)
22. Where I work, there is a system account in the Development Environment
Sat Jan 3, 2015, 03:18 PM
Jan 2015

It is shared amongst 400+ developers. The old group of people in charge would make it something like $w0rdFi$h. The account is totally walled off from access from outside the network, yet the new group of geeks in charge insist on passwords like Gl24%bnGf4!*rt3. So of course, each and every one of us has it written down somewhere because it it is impossible to remember for the once or twice you need it a month.

So by making the password "more secure" they have actually made it much much less secure...

Initech

(100,067 posts)
7. The combination is 12345.
Sat Jan 3, 2015, 02:31 PM
Jan 2015

"12345? Are you crazy? That's the stupidest combination I've ever heard! That's the kind of thing an idiot would have on his luggage!"



karadax

(284 posts)
8. Sentences = best passwords
Sat Jan 3, 2015, 02:33 PM
Jan 2015

Something simple yet personal. Not easy to crack.

It's random but it's something only you would know.

I am more concerned about people leaving the default passwords on their routers than I am iTunes accounts.

Posteritatis

(18,807 posts)
13. I once worked for a company which standardized user passwords
Sat Jan 3, 2015, 02:48 PM
Jan 2015

It actually felt dumber than keeping default passwords, because really guys.

The senior management was really paranoid about wanting access to employee email at all times, so they assigned passwords and wouldn't let users change them without case-by-case permission. As a result, everyone had the exact same scheme for all their accounts, nationwide, with the only differences being specific to the usernames.

I was (among other things) "the computer guy" in my specific office, and was trying to stir up fuss about what's an incredibly catastrophic security policy most of the time I was there. I finally succeeded when they had me help out another branch with something and I made a point of guessing someone's password on their end on the first try.

At that point the local franchise commissioned their own server/email/etc at fairly bonkers cost, to the dismay of the head office who couldn't really say much about that because of the incredible liability issues their policy would launch off. I left shortly afterwards for other projects and they're considerably more secure now, but it's absolutely staggering that in this day and age a scenario like that could even happen.

 

Scootaloo

(25,699 posts)
20. ...Earth below us, drifting, falling | Floating weightless, calling calling home
Sat Jan 3, 2015, 03:11 PM
Jan 2015

...Sorry, you just put an earworm in my head and now i have to give it back

tammywammy

(26,582 posts)
32. The other tips I've heard
Sat Jan 3, 2015, 04:53 PM
Jan 2015

Use a fairy tale like Three Little Pigs = 3L!ttl3P!6$

Or I have a friend that uses a line from a song she likes and use the first letter of each word to make her combo.

 

SheilaT

(23,156 posts)
21. I've been known to use
Sat Jan 3, 2015, 03:12 PM
Jan 2015

French words, with a symbol or two thrown in. A friend of mine who was in the Peace Corps in Malaysia uses Malaysian words. I'm grateful for the monolinguism of most Americans. If I move to France, I guess I'll have to have my friend send me a list of Malaysian words.

 

SheilaT

(23,156 posts)
30. Even better.
Sat Jan 3, 2015, 04:37 PM
Jan 2015

My languages are English, French, Spanish German, and Italian, although my command of the last two is quite limited.

socialist_n_TN

(11,481 posts)
23. The best password formula I've ever heard of is......
Sat Jan 3, 2015, 03:23 PM
Jan 2015

to take the first letter of a line in one of your favorite songs. Capitalize where appropriate and throw in some numbers like 2 for "too" or "to", 4 for "for", 8 for "ate", etc.

To crack this password it would take someone who knew you well enough to know what your fav song is and then figure out which line in that song you used and then figure out which number you changed a word into and how many times you did so. Sounds pretty much impossible to bust that code to me.

 

Aerows

(39,961 posts)
27. Mine are ten minimum, no repeating characters
Sat Jan 3, 2015, 04:29 PM
Jan 2015

use caps, numbers and symbols. You can use a phrase with a known (to you) set of substitutions and get a password that is nearly impossible to crack - but you must include non-repeaters, upper, lower, symbol and numbers of at least ten. Mine is eleven currently, but I change it every couple of months.

Example: Cup0fDel!c1ous or MyD0gH@$fl3as

Easy to remember, hard to hack.

http://passwordmeter.com/

Good place to check them, but obviously don't use your exact password, just a similar one and modify it

Historic NY

(37,449 posts)
28. I keep changing mine, mostly because I changed it and forgot the new one...
Sat Jan 3, 2015, 04:33 PM
Jan 2015

I think one account 6 times.... None here are mine.

Latest Discussions»General Discussion»If you are using any of t...