
For many people, changing the order of the characters in a phrase is their idea of a strong password. So you'd think something complicated like ji32k7au4a83 would make a great password. But according to Have I Been Pwned (HIBP), it's happening more often than you might think.
This interesting tidbit comes from self-proclaimed hardware/software engineer, Robert Ou, who recently asked Twitter followers if they could explain why this seemingly random string of characters has appeared in HIBP over a hundred times.
Have I Been Pwned is a platform started by security expert Troy Hunt to help people find out if their email or personal data has been exposed in any known data breaches. One service it offers is a password lookup that lets you check if your password has been exposed in any data breaches detected by the security community. In this case, “ji32k7au4a83” has been discovered by HIBP in 141 breaches.
Several of Ou's followers quickly figured out the solution to this conundrum. The password comes from the Zhuyin Fuhao system for translating into Mandarin. The reason it appears so often is because "ji32k7au4a83" translates into English as "my password." This practice has been spotted being used quite frequently in Taiwan.
So what's the moral here? We could conclude that people in Taiwan seem to have some bad password-picking practices, just like the rest of us do most of the time, but who knows what's really going on here. You should also do a quick check of the HIBP database to improve your password-creation practices and make sure your seemingly random string of characters doesn't have any other meaning.
