News

Top Websites Allow Tens of Millions Of Users To Create Weak Passwords

Giulio Saggin
Giulio Saggin
Tuesday 5 December 2023
Top Websites Allow Tens of Millions Of Users To Create Weak Passwords
Photo: SecAlerts

Three out of four of the world’s most popular websites are allowing tens of millions of users to create weak passwords and, in the process, failing to meet minimum requirement standards.

Researchers at Georgia Tech (https://www.cc.gatech.edu/news/largest-study-its-kind-shows-outdated-password-practices-are-widespread) developed an automated tool - the first of its kind - to assess password creation policies and found that more than 10% of websites failed when it came to password length requirements.

The tool explored the database of one million websites and pages in the Google Chrome User Experience Report (CrUX) and showed that many sites allowed very short passwords, didn't block common passwords and used outdated requirements such as complex characters.

Other findings included:

- Sites used (outdated) guidelines from 2004 - More than half of the websites accepted passwords of six characters or less - 75% of websites failed to require the recommended eight-character minimum - Nearly a third did not support spaces or special characters - 12% of had no length requirements

Additional to this, less than a third of websites enforced a password block list, so thousands are vulnerable to a password spraying attack i.e. hacker using common passwords to break into accounts.

Not many of us like passwords. Who wants to change one or more every few months or follow all sorts of guidelines to set up one? Humans are creatures of habit and use patterns when choosing or changing passwords. This makes guessing passwords easier, which plays straight into the hands of hackers.

If this study is any guide, many websites are more concerned with customer satisfaction than security, and 99% of the time a happy customer wins out.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203