Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchYes—SplashData’s January 20, 2014 announcement put “123456” at number one, ahead of “password,” in its annual list of commonly used, easily guessed passwords. The ranking reflected exposed passwords, including material linked to the Adobe breach; it was not a representative survey of all internet users or a current ranking.
What SplashData’s ranking actually showed
SplashData said “123456” had taken the top spot from “password” for the first time since the company began publishing its annual list. The claim is about the order in that particular ranking, announced January 20, 2014—not proof that “123456” was the most common password across all accounts. SplashData’s January 20, 2014 announcement described the ranking as influenced by passwords exposed online after Adobe’s security breach, including a large collection posted by Stricture Consulting Group.
TIME’s January 20, 2015 report on SplashData’s 2014 list said the company analyzed files containing more than 3.3 million passwords leaked during 2014. That number describes the files in the dataset—not the number of people using “123456” or “password.” TIME’s account of the 2014 ranking likewise makes clear that the list came from exposed credentials.
Why “123456” beat “password”
The list ranked passwords found in leak material by how common and easy to guess they were. “123456” is a simple sequence; “password” is a common word. Their positions show that both appeared often enough in the analyzed exposed-password material to rank highly. The available evidence does not establish why individual people chose either one, or that the ranking tested every password in use against a universal security standard.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Because the material was leaked rather than collected through a random, representative survey, the ranking cannot tell you what share of all users had weak passwords. Nor can it establish how any particular account was compromised. It is evidence that predictable choices appeared in the exposed datasets SplashData analyzed.
Is this the latest worst-password list?
No. This is a 2014 ranking announced in January 2014, with TIME reporting on the 2014 list in January 2015. It should be read as historical password-security news, not as a current leaderboard or a measurement of today’s password habits.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What to do instead of using a weak password
NIST’s current public guidance, on a page updated August 20, 2025, recommends multifactor authentication (MFA), passkeys where available, and password managers for accounts that still rely on passwords. NIST’s password guidance recommends at least 15 characters when you must create a password yourself. Its implementation FAQ for SP 800-63B-4 says services should support password managers and autofill, and summarizes the applicable standard as requiring a 15-character minimum for single-factor passwords, disallowing composition rules, and not requiring routine periodic password changes. These are NIST recommendations and requirements for services covered by that standard; they do not mean every website already follows them. NIST SP 800-63B-4 implementation FAQs
Quick Recap
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #4
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
- Replace predictable or reused passwords. If an account still uses “123456,” “password,” or an obvious variation, change it to a distinct credential. Do not reuse the replacement on another service: exposed credentials can be tried elsewhere in a practice known as password stuffing.
- Use a password manager for password-based accounts. It can generate and store a different password for each service, making it easier to avoid reuse. Choose one with security and recovery options that suit your needs, and make sure it supports the devices and autofill features you use.
- Turn on MFA, or use a passkey if the service offers one. NIST lists security keys or USB dongles, authenticator apps, push notifications, and text codes among MFA methods; these methods do not offer the same level of protection, and text codes are particularly vulnerable compared with stronger choices. NIST describes passkeys as phishing-resistant and able to avoid memorization. Their usefulness depends on whether the service supports them and whether you can recover access if you lose a device.
- Make a manually created password long. If a service requires a password you must create and remember, follow NIST’s public recommendation of at least 15 characters. A memorable passphrase can make a longer password easier to use.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

