top of page

“They Knew Which Words I’d Use Before I Did”: The Password Guessing Game Nobody Told You Changed

For Seniors (55–90)



A dictionary attack works differently than brute force — instead of trying every possible combination blindly, it runs through a list of real words and common passwords, the kind people actually tend to use: a spouse’s name, a birth year, a beloved pet, a favorite sports team. It’s called a “dictionary” because it’s working from real language, not random noise, which historically made it faster than blind guessing.

The update worth knowing about is where that “dictionary” comes from now. These word lists can be built automatically from patterns found in enormous collections of previously leaked passwords, and some tools go a step further, drawing on publicly available details — a pet’s name mentioned online, a hometown, a graduation year — to build a shorter, much more targeted list specific to one person rather than a generic one.


This CISA public service video, though framed around a different tool, captures the underlying point well: the defense that actually matters isn’t a cleverer password, it’s a second layer entirely. Secure Our World: Multi-Factor Authentication (CISA)


Here’s a simple way to picture it: imagine a burglar with a giant ring of common house keys, trying the ones statistically most likely to fit before wasting time on rare ones. Most burglaries with a key ring like that succeed on ordinary, common locks — not rare or unusual ones. A password built from real words and personal details is, in exactly this sense, a common lock. It doesn’t matter how meaningful the word is to you. What matters is how common that pattern is across everyone else, too.


Practical steps that genuinely help:


1.          Avoid using pet names, family names, birthdays, or hometowns as passwords or as the security-question answers protecting them — these are exactly the all too familiar details targeted lists are built from, and they’re often sitting in public view without you realizing it.


2.          If you’ve reused one password across several accounts, treat that as the highest priority to fix first, starting with email and banking, since one leaked password can otherwise unlock several accounts at once.


3.          Enable multi-factor authentication wherever it’s offered, so that even a correctly guessed password isn’t enough on its own to get into your account.


4.          Ask about a password manager the next time a family member offers to help with something tech-related. It’s a genuinely useful use of ten minutes of someone’s time, and it removes the need to invent — or remember — clever passwords ever again.


The habit worth keeping isn’t suspicion of every message that arrives. It’s simply this: the words that feel personal and meaningful to you are, unfortunately, exactly the words a guessing list is built to try first and eventually crack with ease.


________________________________________________________________

This post is part of a series inspired by and meant to complement AI Safety for the Everyday User (In 10 Easy Steps) by Terrence “TerrenceTech” Williams — a plain-language guide covering sixteen classic scams and the ten concrete habits that stop them. The full book goes deeper into the “why” behind each one and lays out a complete, step-by-step action plan.

 
 
 

Recent Posts

See All

Comments


bottom of page