Every year the “most common passwords” lists come out, and every year 123456 is sitting at the top, exactly where it was a decade ago. People react with a kind of despair — how, after all this, are we still here? I stopped being surprised years ago, because the lists aren’t really measuring stupidity. They’re measuring a design failure. The people choosing 123456 aren’t ignoring security advice; they’ve quietly decided this particular account isn’t worth the effort, and the system gave them no reason to think otherwise.

It’s not laziness — it’s a rational response to friction

Picture the moment these passwords get created. You want to read one article, buy one thing, or post once to a forum, and a wall appears: create an account. You didn’t want an account. You wanted the thing behind it. So you do the least work that gets you through the door, and the least work is 123456.

That’s not carelessness, it’s a fair trade from the user’s point of view — they’ve judged the account worthless and priced their effort accordingly. The trouble is they’re usually wrong about “worthless,” because of what happens next (more on that below). And the truly awful passwords cluster exactly where you’d expect: the throwaway logins people are forced to make and never expect to care about.

Password fatigue is the bigger force

The deeper driver is sheer volume. The average person now juggles well over a hundred online accounts. Ask any human to invent, and remember, a hundred unique sixteen-character strings and you’re not asking for discipline — you’re asking for something the brain physically cannot do. So it does what brains do under overload: it falls back on patterns, repetition and the path of least resistance. 123456 is just the most honest expression of that exhaustion.

This is why “just try harder” has failed for thirty years. It’s advice that fights human cognition instead of working with it. You cannot lecture your way out of a memory problem.

The hall of shame, and why it’s a map for attackers

These are the passwords that consistently top the global leaked-credential lists. They aren’t a curiosity — they’re literally the first guesses any attacker makes, because they’re the cheapest hits available.

RankPasswordRankPassword
1123456612345678
2password7iloveyou
31234567898admin
4qwerty9welcome
51234510password123

Here’s the part the “worthless account” logic misses. A throwaway login isn’t isolated. If you used 123456 and reused it — or used it with an email you use elsewhere — that worthless forum becomes the thread an attacker pulls to unravel accounts you very much do care about, via credential stuffing. The account felt disposable. The password habit attached to it wasn’t.

The only fix that actually works

You don’t solve a memory problem with more memory. You solve it by removing memory from the equation. The single change that ends this whole cycle is a password manager: you memorise one strong passphrase, and the software generates, stores and fills a unique random password for every site — including the throwaway ones you’d otherwise hand 123456.

That’s the quiet trick. Once the cost of a strong unique password drops to zero effort, the rational response flips. There’s no longer any reason to reach for 123456, because the secure option is now the easy one. We didn’t fix this by making people care more. We fixed it by making the right thing effortless.

If you want the method for that one master passphrase, I lay it out in how to create a strong password. And if you suspect you’re using a variation of something on that table, run it through the PassGuard Check tester and see how fast it falls — locally, in your browser, with nothing you type ever stored or sent.