Study: 154 users logged into 26 sites with fewer than 10 passwords, ~60% reused
Carnegie Mellon researchers tracked the logins of 154 people for an average of 147 days via a browser extension that hashed passwords on-device. Participants logged into 26 web domains each using fewer than 10 distinct passwords, with roughly 60% reused outright or built from fragments of other passwords. On financial sites, 85% of passwords also appeared elsewhere.
- 154 participants logged into 26 sites each with fewer than 10 distinct passwords
- About 60% of passwords were reused outright or built from 4+ character fragments
- 85% of passwords on financial sites also appeared in unrelated categories
- Only 19 of 154 participants had a password manager, with no measurable effect on reuse
Read next
Security