"Weak password" sounds like a vibe, but it has a precise, operational meaning: a password is weak if it appears early in the sequence of guesses that real cracking tools produce. Those tools don't guess alphabetically - They guess in probability order, trained on billions of leaked human passwords, trying the likeliest candidates first. Weakness, then, is predictability, and predictability leaves fingerprints. Here are nine of them - Read them as an audit checklist against your own current passwords, and count your flags.

Red flag 1: It's short

Under 12 characters, physics is against you regardless of content. Each character multiplies the search space; too few characters and even exhaustive search becomes affordable. A fully random 8-character password - The strongest possible 8 - Sits around 53 bits, which a GPU rig cracking a fast hash can exhaust in hours. Below that, minutes. Length is the one flag that dooms even random passwords, which is why every modern floor starts at 12 and sensible practice starts at 16.

Red flag 2: Its core is a dictionary word or name

dragon, chelsea, pikachu, a spouse's name, a city - If the heart of your password is a word, your password is one guess plus decoration. Wordlists compiled from breaches contain not just English vocabulary but names, teams, bands, brands, slang, and other languages, and they're tried first, precisely because most human passwords are built this way. The mechanics - Wordlists plus mangling rules at billions of guesses per second - Are laid out in dictionary attacks. A word is a single point in a small search space, no matter how long the word is.

Red flag 3: Predictable decoration

Capitalized first letter, digits at the end, ! as the final character, @ for a, 0 for o. These transformations feel like they upgrade a word into a "complex" password; statistically they're the most common patterns in existence, encoded as one-line rules in every cracking toolkit. Dragon2024! is not meaningfully harder than dragon - It's the same wordlist entry with the same standard rules applied. Decoration is compliance theater; entropy comes only from unpredictability.

Red flag 4: It contains a year or date

Years - Birth years, graduation years, the current year, anniversaries - Are so prevalent as suffixes that rules append every plausible year to every wordlist candidate as a matter of course. Dates in any format (0714, july14, 140792) carry only a few bits each while feeling substantial. If any four digits in your password mean something on a calendar, an attacker's rule set already generates them.

Red flag 5: It's a keyboard pattern

qwerty, 1q2w3e4r, zxcvbn, asdfgh, 1qaz2wsx - Walks across the keyboard look random and rank among the most common passwords on Earth. Every geometric stroll, in every direction, in every regional layout, is enumerated in wordlists. The same goes for repeats (aaaaaa, 123123) and sequences (abcdef, 654321). If your fingers can find it by following adjacent keys, so can the first thousand guesses. The evidence is grimly visible in the most common passwords, a chart that keyboard walks have never once missed.

Red flag 6: It's built from facts about you

Pet, kid, birthday, street, team, plate number. This flag has two failure modes. Against mass attacks, personal facts fail because they're human-typical - Names and dates are wordlist staples. Against targeted attacks, they fail because they're discoverable - Your social profiles happily volunteer the pet, the team, and the birthday to anyone who looks. Personal also means memorable to the wrong people: exes, coworkers, and acquaintances outperform strangers at guessing it. Reducing how linkable your accounts are helps here too - Distinct handles from a username generator keep one profile's oversharing from seeding guesses against another.

Red flag 7: It's reused anywhere

The stealth flag: this one weakens a password that may be flawless on paper. A unique 20-character random string is excellent; the same string on five sites is only as strong as the weakest site holding it. When any one of them leaks, automated credential stuffing replays the pair against hundreds of major services within hours. Reuse converts "one obscure forum got hacked" into "my email, cloud storage, and PayPal got hacked." Strength cannot compensate for reuse; they're independent axes, and you need both.

Red flag 8: It has already leaked

A password that appears in breach corpora is burned forever, no matter how strong it looks - Those corpora are the wordlists. Have I Been Pwned's Pwned Passwords database catalogs hundreds of millions of real compromised passwords precisely so people and sites can screen for them; NIST guidance now tells services to block known-breached candidates at signup. Check your email at haveibeenpwned.com and treat any password from a breached account as public knowledge.

Red flag 9: It predates your current habits

Old passwords are weak passwords with seniority. The ones you minted years ago - Before you used a generator, before length norms rose, back when one favorite password roamed every site - Are still guarding forgotten accounts, and forgotten accounts still hold your email address, security answers, and payment details. Age also raises the odds it has appeared in some breach along the way. If you can't remember creating it recently, assume flags 1–8 apply.

Random 16-char password
~105 bits
Random 8-char password
~53 bits
Word + year + symbol
~25 bits
Top-1000 common password
~10 bits

The scorecard

# Red flag Why it fails Guesses to reach it
1 Under 12 characters Search space affordable to exhaust Varies - Hours if random, instant if not
2 Dictionary word core Wordlists tried first Thousands
3 Predictable decoration Standard mangling rules Millions
4 Year or date included Auto-appended by rules Millions
5 Keyboard pattern Enumerated in every wordlist Hundreds
6 Personal facts Human-typical and discoverable Thousands (targeted: fewer)
7 Reused Breached once, replayed everywhere One - No cracking needed
8 Already leaked Literally in the wordlist One
9 Predates your habits Inherits flags 1–8, plus breach years Varies

A password is weak if a machine that has studied a billion human passwords would think of it. The only strings such a machine never thinks of are the ones no human thought of either - Which is why the fix is dice, not discipline.

Fixing all nine at once

The flags share a single root - Human generation - So they share a single cure. A password generator produces strings with no word, no date, no pattern, no personal content, at whatever length you set: flags 1 through 6 vanish by construction. Storing each one uniquely in a password manager clears flag 7, refusing to carry forward pre-manager passwords clears 8 and 9, and a password strength checker - One that models dictionary patterns rather than counting character classes - Gives you an honest verdict on anything you're unsure about, locally in your browser.

Don't boil the ocean: fix email, banking, and your master password today, then let your manager's audit view flag the rest and replace them as you log in. A structured version of this cleanup - Fifteen minutes, prioritized - Is the whole point of the password hygiene checklist.

FAQ

How many red flags make a password "weak enough to worry about"?

One is enough if it's flags 5, 7, or 8 - Patterns and leaked/reused passwords fall to the first wave of any attack. Word-based passwords with decoration (flags 2–4 together, the most common combination) typically fall within minutes of an offline attack. Realistically: any flagged password guarding email, money, or your password manager should be replaced this week.

Is a weak password acceptable for accounts I don't care about?

Only if the account truly holds nothing - No card on file, no personal data, no email address you use elsewhere, no OAuth links to other services. Such accounts are rarer than assumed, and the habit is the real cost: junk-tier passwords have a way of getting promoted when a "throwaway" account suddenly matters. Since a generator makes strong free, tiering passwords by care level saves nothing.

My password fails several flags but has never been hacked. Doesn't that prove it's fine?

It proves the hashed database it lives in hasn't leaked yet, or leaked without making news. Cracking happens offline, silently, after a breach you may learn about years late - Survival to date is not evidence of strength, the same way an untested smoke detector isn't proven by the absence of fires. The flags measure what happens on the day it's tested.

Are longer human-made passwords okay - Say, a full sentence?

Better than a decorated word, weaker than their length implies. Real sentences obey grammar and word-frequency statistics, and phrase-level attacks model exactly that; song lyrics and quotes are effectively wordlist entries. A sentence can be a reasonable memorized password if it's long and genuinely obscure, but randomly chosen words are strictly stronger per word and just as memorable.

What should I check first if I can only audit one thing?

Reuse on your primary email account. Email is the reset hub for everything else, so a reused email password is the single highest-leverage weakness a person can have - One breach anywhere becomes account takeover everywhere. Give email a unique generated password and 2FA before touching anything else.