Platform
Solutions
Resources
Company
Platform
Solutions
Resources
Company

Nick Morgan
∙
Can Someone Guess Your Password?


Nick Morgan
∙
Can Someone Guess Your Password?


Nick Morgan
∙
Can Someone Guess Your Password?

Yes, more easily than most people think. A Google/Harris Poll study found that 27% of Americans have tried to guess someone else's password, and 17% succeeded. That's not sophisticated hacking, that's just knowing someone's birthday or their dog's name.
As World Password Day rolls around, the password, still the cornerstone of digital security for most accounts, is worth a hard look. Start with yourself: where does your password actually come from?
What Your Password Reveals About You
If your name or birthday shows up somewhere in your password, you're in the majority. The same Google/Harris Poll study found:
What's in the password | Share of Americans |
|---|---|
Name or birthday | 59% |
Pet's name | 33% |
Own name | 22% |
Partner's name | 15% |
Child's name | 14% |
It's memorable. That's exactly the flaw. Anything memorable to you is discoverable by someone else, especially if they know you personally or can piece it together from social media. A hacker who knows their target doesn't need to guess randomly; they can start with the short list of things people actually use.
The Guessing Game Is More Common Than You'd Think
Of the 27% of Americans who've tried guessing someone else's password, 17% got it right. That's not a niche threat aimed at high-value targets, it threatens everything from a shared streaming login to online banking.
"Random" Passwords Aren't Always Safer
Maybe you skip the personal-details approach and go for something quick instead. Some of the most common passwords that don't follow the name pattern: "abc123," "Password," and "123456," with honorable mentions for "iloveyou," "Qwerty," and "picture1." NordPass's annual most-common-passwords research tracks exactly this list every year, and the pattern hasn't changed: these passwords take a fraction of a second to crack, personal information or not.
The Two Things That Actually Help: Length and Complexity
There are two changes you can make right now that turn a password from a few-second breach into one that takes years, not seconds, to crack: make it longer, and make it more complex.
Scientific American's breakdown of the math shows why length matters so much more than people expect. Doubling a password from six characters to twelve doesn't just double the difficulty, it multiplies the number of possible combinations by roughly 62 trillion. If cracking every possible combination in the six-character space took one second, doing the same for the twelve-character space would take around two million years.
Reusing Passwords Undoes All of That Work
Even a strong password only protects the accounts it's actually used on. Google's research found 52% of users reuse the same password across multiple (though not all) accounts, and 13% use one password for literally everything. In that second group, a single compromised password hands an attacker the keys to every account that person owns, no additional cracking required.
What Actually Fixes This
Longer, more complex, unique-per-account passwords help, but they also ask a lot of ordinary human memory, which is exactly why people fall back on birthdays and pet names in the first place. A security-first password manager removes that trade-off: it can generate and store passwords too long and random for anyone to guess, without asking you to remember them.
The more durable fix goes a step further. As we've written before, the password itself, not just weak ones, is the recurring point of failure. Multi-factor authentication, or more precisely the right factors used correctly, closes the gap for accounts that still require a password. But the strongest position is removing the guessable credential entirely: usernameless, passwordless login gives an attacker nothing to guess in the first place, no birthday, no pet's name, no "abc123."
FAQ
How easy is it for someone to guess my password?
Easier than most people assume. 27% of Americans have tried guessing someone else's password, and 17% succeeded, largely because most people build passwords around personal information (a name, a birthday, a pet) that's often discoverable through social media or personal familiarity.
Does making a password longer really make that much difference?
Yes, more than adding complexity alone. Going from a 6-character to a 12-character password multiplies the number of possible combinations by roughly 62 trillion, turning a crackable password into one that would take millions of years to brute-force.
Is reusing a strong password across multiple accounts still risky?
Very. A strong password only protects the specific account it's used on. If that password (or the site storing it) is ever breached, every other account using the same password is exposed too. 13% of users reuse one password for every account they own.
What's a better long-term fix than just choosing stronger passwords?
Removing the password as a guessable secret in the first place. A password manager helps in the short term by generating and storing complex, unique passwords. Usernameless, passwordless authentication goes further by eliminating the guessable credential entirely.
The Bottom Line
Laughing at cheesy passwords, or guessing your way into a friend's Netflix account, is easy precisely because the underlying flaws in password security are so common. Whether your password is your first name and birthday or a genuinely complex string of characters, this World Password Day is a good moment to stop making a hacker's job easy, and to start thinking about getting rid of usernames and passwords altogether.
Yes, more easily than most people think. A Google/Harris Poll study found that 27% of Americans have tried to guess someone else's password, and 17% succeeded. That's not sophisticated hacking, that's just knowing someone's birthday or their dog's name.
As World Password Day rolls around, the password, still the cornerstone of digital security for most accounts, is worth a hard look. Start with yourself: where does your password actually come from?
What Your Password Reveals About You
If your name or birthday shows up somewhere in your password, you're in the majority. The same Google/Harris Poll study found:
What's in the password | Share of Americans |
|---|---|
Name or birthday | 59% |
Pet's name | 33% |
Own name | 22% |
Partner's name | 15% |
Child's name | 14% |
It's memorable. That's exactly the flaw. Anything memorable to you is discoverable by someone else, especially if they know you personally or can piece it together from social media. A hacker who knows their target doesn't need to guess randomly; they can start with the short list of things people actually use.
The Guessing Game Is More Common Than You'd Think
Of the 27% of Americans who've tried guessing someone else's password, 17% got it right. That's not a niche threat aimed at high-value targets, it threatens everything from a shared streaming login to online banking.
"Random" Passwords Aren't Always Safer
Maybe you skip the personal-details approach and go for something quick instead. Some of the most common passwords that don't follow the name pattern: "abc123," "Password," and "123456," with honorable mentions for "iloveyou," "Qwerty," and "picture1." NordPass's annual most-common-passwords research tracks exactly this list every year, and the pattern hasn't changed: these passwords take a fraction of a second to crack, personal information or not.
The Two Things That Actually Help: Length and Complexity
There are two changes you can make right now that turn a password from a few-second breach into one that takes years, not seconds, to crack: make it longer, and make it more complex.
Scientific American's breakdown of the math shows why length matters so much more than people expect. Doubling a password from six characters to twelve doesn't just double the difficulty, it multiplies the number of possible combinations by roughly 62 trillion. If cracking every possible combination in the six-character space took one second, doing the same for the twelve-character space would take around two million years.
Reusing Passwords Undoes All of That Work
Even a strong password only protects the accounts it's actually used on. Google's research found 52% of users reuse the same password across multiple (though not all) accounts, and 13% use one password for literally everything. In that second group, a single compromised password hands an attacker the keys to every account that person owns, no additional cracking required.
What Actually Fixes This
Longer, more complex, unique-per-account passwords help, but they also ask a lot of ordinary human memory, which is exactly why people fall back on birthdays and pet names in the first place. A security-first password manager removes that trade-off: it can generate and store passwords too long and random for anyone to guess, without asking you to remember them.
The more durable fix goes a step further. As we've written before, the password itself, not just weak ones, is the recurring point of failure. Multi-factor authentication, or more precisely the right factors used correctly, closes the gap for accounts that still require a password. But the strongest position is removing the guessable credential entirely: usernameless, passwordless login gives an attacker nothing to guess in the first place, no birthday, no pet's name, no "abc123."
FAQ
How easy is it for someone to guess my password?
Easier than most people assume. 27% of Americans have tried guessing someone else's password, and 17% succeeded, largely because most people build passwords around personal information (a name, a birthday, a pet) that's often discoverable through social media or personal familiarity.
Does making a password longer really make that much difference?
Yes, more than adding complexity alone. Going from a 6-character to a 12-character password multiplies the number of possible combinations by roughly 62 trillion, turning a crackable password into one that would take millions of years to brute-force.
Is reusing a strong password across multiple accounts still risky?
Very. A strong password only protects the specific account it's used on. If that password (or the site storing it) is ever breached, every other account using the same password is exposed too. 13% of users reuse one password for every account they own.
What's a better long-term fix than just choosing stronger passwords?
Removing the password as a guessable secret in the first place. A password manager helps in the short term by generating and storing complex, unique passwords. Usernameless, passwordless authentication goes further by eliminating the guessable credential entirely.
The Bottom Line
Laughing at cheesy passwords, or guessing your way into a friend's Netflix account, is easy precisely because the underlying flaws in password security are so common. Whether your password is your first name and birthday or a genuinely complex string of characters, this World Password Day is a good moment to stop making a hacker's job easy, and to start thinking about getting rid of usernames and passwords altogether.
Yes, more easily than most people think. A Google/Harris Poll study found that 27% of Americans have tried to guess someone else's password, and 17% succeeded. That's not sophisticated hacking, that's just knowing someone's birthday or their dog's name.
As World Password Day rolls around, the password, still the cornerstone of digital security for most accounts, is worth a hard look. Start with yourself: where does your password actually come from?
What Your Password Reveals About You
If your name or birthday shows up somewhere in your password, you're in the majority. The same Google/Harris Poll study found:
What's in the password | Share of Americans |
|---|---|
Name or birthday | 59% |
Pet's name | 33% |
Own name | 22% |
Partner's name | 15% |
Child's name | 14% |
It's memorable. That's exactly the flaw. Anything memorable to you is discoverable by someone else, especially if they know you personally or can piece it together from social media. A hacker who knows their target doesn't need to guess randomly; they can start with the short list of things people actually use.
The Guessing Game Is More Common Than You'd Think
Of the 27% of Americans who've tried guessing someone else's password, 17% got it right. That's not a niche threat aimed at high-value targets, it threatens everything from a shared streaming login to online banking.
"Random" Passwords Aren't Always Safer
Maybe you skip the personal-details approach and go for something quick instead. Some of the most common passwords that don't follow the name pattern: "abc123," "Password," and "123456," with honorable mentions for "iloveyou," "Qwerty," and "picture1." NordPass's annual most-common-passwords research tracks exactly this list every year, and the pattern hasn't changed: these passwords take a fraction of a second to crack, personal information or not.
The Two Things That Actually Help: Length and Complexity
There are two changes you can make right now that turn a password from a few-second breach into one that takes years, not seconds, to crack: make it longer, and make it more complex.
Scientific American's breakdown of the math shows why length matters so much more than people expect. Doubling a password from six characters to twelve doesn't just double the difficulty, it multiplies the number of possible combinations by roughly 62 trillion. If cracking every possible combination in the six-character space took one second, doing the same for the twelve-character space would take around two million years.
Reusing Passwords Undoes All of That Work
Even a strong password only protects the accounts it's actually used on. Google's research found 52% of users reuse the same password across multiple (though not all) accounts, and 13% use one password for literally everything. In that second group, a single compromised password hands an attacker the keys to every account that person owns, no additional cracking required.
What Actually Fixes This
Longer, more complex, unique-per-account passwords help, but they also ask a lot of ordinary human memory, which is exactly why people fall back on birthdays and pet names in the first place. A security-first password manager removes that trade-off: it can generate and store passwords too long and random for anyone to guess, without asking you to remember them.
The more durable fix goes a step further. As we've written before, the password itself, not just weak ones, is the recurring point of failure. Multi-factor authentication, or more precisely the right factors used correctly, closes the gap for accounts that still require a password. But the strongest position is removing the guessable credential entirely: usernameless, passwordless login gives an attacker nothing to guess in the first place, no birthday, no pet's name, no "abc123."
FAQ
How easy is it for someone to guess my password?
Easier than most people assume. 27% of Americans have tried guessing someone else's password, and 17% succeeded, largely because most people build passwords around personal information (a name, a birthday, a pet) that's often discoverable through social media or personal familiarity.
Does making a password longer really make that much difference?
Yes, more than adding complexity alone. Going from a 6-character to a 12-character password multiplies the number of possible combinations by roughly 62 trillion, turning a crackable password into one that would take millions of years to brute-force.
Is reusing a strong password across multiple accounts still risky?
Very. A strong password only protects the specific account it's used on. If that password (or the site storing it) is ever breached, every other account using the same password is exposed too. 13% of users reuse one password for every account they own.
What's a better long-term fix than just choosing stronger passwords?
Removing the password as a guessable secret in the first place. A password manager helps in the short term by generating and storing complex, unique passwords. Usernameless, passwordless authentication goes further by eliminating the guessable credential entirely.
The Bottom Line
Laughing at cheesy passwords, or guessing your way into a friend's Netflix account, is easy precisely because the underlying flaws in password security are so common. Whether your password is your first name and birthday or a genuinely complex string of characters, this World Password Day is a good moment to stop making a hacker's job easy, and to start thinking about getting rid of usernames and passwords altogether.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.
