Researchers tracked the passwords 154 people used online for an average of 147 days and found them logging into 26 websites with fewer than 10 unique passwords — roughly 60 percent were reused outright or built from pieces of passwords they were already using elsewhere

Date:

The Real Story Behind Password Reuse: Insights from a Five-Month Study

For about five months, a browser extension quietly observed the login habits of 154 individuals on their home computers. The study, conducted by researchers at Carnegie Mellon University, ensured privacy by hashing all passwords locally before any data was transmitted. What they collected was not the actual passwords but metadata: the length, character composition, the websites involved, and whether a password had been previously used by the same person.

Surprisingly often, passwords reappeared.

What 154 People Actually Typed

Sarah Pearman and her team presented their findings at a 2017 computer security conference, tracking participants for an average of 147 days each. Across this period, each individual logged into approximately 26 different web domains, yet used fewer than 10 unique passwords in total. This limited variety highlights a persistent preference for password reuse, a habit that remains prevalent despite widespread warnings from security experts.

About 60 percent of these distinct passwords were recycled either as identical strings on different sites or as variations built around a shared substring of four or more characters. Notably, banking sites received no special treatment: roughly 85 percent of passwords used on financial websites were also employed elsewhere, often in completely unrelated categories. For example, a password used for a savings account might also be the login credential for a shoe shop.

What Partial Reuse Looks Like Up Close

Partial reuse often involves minor modifications, typically the addition of a single character. Among passwords with overlapping substrings, the most common difference was just one extra character. Digits, in particular, emerged as a strong predictor of reuse, increasing the likelihood of password recycling by more than twelve times in the Carnegie Mellon model.

The researchers suggest this pattern arises because including numbers helps passwords meet the often stringent and inconsistent character requirements imposed by many websites. As a result, users tend to append digits to a base password to comply with these rules, inadvertently extending the life of the original string across multiple sites.

The Tidy Minority Had Barely Any Accounts

Among the participants, ten individuals mostly created unique passwords for each site visited. While this approach aligns with best security practices, it came with a caveat: these participants typically had eight or fewer online accounts and were active on their computers on just 17 percent of the days they were enrolled in the study. This suggests that strict password discipline may be more feasible for users with limited digital footprints.

On the other hand, the majority of participants—94 in total—engaged in both outright password copying and modification. These “heavy users” averaged 32 accounts each, indicating that password reuse becomes far more common as the number of accounts grows. The study found that password management discipline tends to hold up to about eight accounts but diminishes significantly once the number reaches thirty.

The Password Manager Result, With a Handbrake

Only 19 out of the 154 participants in the study had a password manager installed. Interestingly, the presence of a password manager showed no measurable effect on either password reuse or strength. However, this finding should be interpreted cautiously: the sample size using password managers was small, and the software could not distinguish between truly random passwords and those manually created by users and stored.

Supporting this nuance, a study by Rick Wash and colleagues at Michigan State University, which observed 134 participants over six weeks, reported an average password reuse rate ranging from 1.7 to 3.4 websites per password. Unlike the Carnegie Mellon research, Wash’s study did not account for partial reuse, so the higher numbers reflect a different measurement approach.

Why a Recycled Password Is Worth Money

The dangers of password reuse extend beyond mere convenience. Vast “combo lists” of email and password pairs, collected from past data breaches, circulate widely in underground markets. Troy Hunt, the Australian security expert behind the breach notification service Have I Been Pwned, has extensively documented this trade in his analysis of credential stuffing attacks.

Automated tools use these lists to try stolen credentials across unrelated websites, often with alarming success. Defending against such attacks is challenging because successful logins appear identical to legitimate user activity, making detection difficult. In essence, a password reused from a defunct hobby forum can become the key to accessing an email account or other sensitive services.

The Rules That Encouraged This Have Been Withdrawn

Recognizing the pitfalls of outdated password policies, the US National Institute of Standards and Technology (NIST) finalized revision 4 of its digital identity guidelines in 2025. The password section reads almost like a quiet apology for decades of complex, often counterproductive requirements.

Websites are now advised to stop demanding arbitrary mixtures of character types and avoid forced periodic password changes unless there is evidence of compromise. They must also support password managers and autofill technologies and check new passwords against blocklists of known leaked credentials.

These updated standards directly target the behaviors recorded by the Carnegie Mellon extension: the reliance on a small set of memorable passwords, tweaked slightly with digits or other minor changes, and reused extensively across an individual’s online life. The new approach assumes that machines, not humans, will handle password memorization.

For anyone who has ever stuck a “1” at the end of a password to satisfy a signup form, this shift could not come soon enough.

Here

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Popular

More like this
Related

A startup founder who served time in prison is looking to court an untapped market: ex-cons

From Prison to Entrepreneurship: Richard Bronson’s Journey to Empower...

Popular AI leaderboard Arena nearly doubles valuation to $3.1B valuation in 10 months

Arena’s Rapid Growth and New Funding Milestone Arena, the AI...

China’s Manus raises over $500M in first funding round since split with Meta

Manus Secures Over $500 Million in Landmark Funding Round...

Healthleap raises $38M for its AI that flags hospital patients who may need a closer look

Healthleap Secures $38 Million to Advance AI-Driven Patient Risk...