Skip to content

Commit ae5b984

Browse files
committed
Gathering-weak-npm-credentials: minor number fix
1 parent d369da3 commit ae5b984

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

Gathering-weak-npm-credentials.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ Taking dependencies into an account, to my estimations about 52% of the ecosyste
5252
* One of those 4 users from the top-20 list set their password back to the leaked one shortly after it was reset (so it got reset again).
5353
* At least one password was significantly inappropriate — to the extent that one wouldn't want that to be linked to them online and could be publicly blamed in that case (i.e. not just a swearword). [Don't use offensive passwords](https://medium.com/@malcomvetter/offensive-passwords-451371ccd02e) — those could (and in this case were) leaked to the public in cleartext.
5454
* **662 users had password «`123456`», 168 — «`123`», 115 — «`password`»**.
55-
* **10% of users reused their leaked passwords**: 9.4% — directly, and 0.6% — with very minor modifications.
55+
* **10% of users reused their leaked passwords**: 9.7% — directly, and 0.6% — with very minor modifications.
5656
* Total downloads/month of the unique packages which I got myself publish access to was 1 946 302 172, that's **20% of the total number of d/m** directly.
5757

5858
### Packages

0 commit comments

Comments
 (0)