Additional resource for the lesson “Dictionary Attacks: Why Meaningful Passwords Fall First” — Online Security course
A dictionary attack does not try every possible password. It tries the likely ones — words, names, dates, the small variations people reach for. It works because most passwords are chosen to be remembered, and anything memorable is, by definition, predictable.
A. Why this matters
A dictionary attack runs through lists: common words, popular names, cities, football teams, birth years, and the small edits people make to them — swapping an a for a 4, adding an exclamation mark at the end.
It is much faster than trying every combination, because it does not try everything. It tries what people actually choose. And people choose things they can remember.
The key idea: the quality that makes a password easy to recall is the same quality that puts it in somebody’s list. The way out is not a better memory — it is not having to remember it at all.
This is worth understanding rather than simply obeying, because it changes what ‘a good password’ means. It is not about looking complicated. It is about being unpredictable.
B. Key concepts
Six ideas, each with what it changes for you.
Dictionary attack
A program that tries words and phrases from dictionaries and lists of leaked passwords, one after another, including near-miss variants like P4ssword!.
Why it matters to you: Knowing the method is what makes the advice concrete: avoid anything a list could contain, rather than simply adding a symbol to what you already use.
Passwords built from personal data
Names, birthdays, a team you support, the city you live in, a nickname. These go into personalised lists built for a specific person.
Why it matters to you: Anything visible on your social profiles can be assembled into a shortlist. The details that make a password feel like yours are the ones that give it away.
Long, non-obvious passphrases
Several unrelated words together, ideally with a number and a symbol. Long enough to resist brute force, unpredictable enough to sit outside any list.
Why it matters to you: You get both properties at once — and, unlike a random string, you can still type it from memory when you have to.
Password uniqueness
One password per service, never repeated. When a site is breached, the exposure ends there.
Why it matters to you: This is what stops a single leak from becoming several. It matters more than how good any individual password is.
Credential stuffing
Attackers taking passwords exposed in one breach and trying them automatically across many other services.
Why it matters to you: It explains why reuse is the specific habit worth breaking first: the attack needs no guessing at all, only your habit.
A second factor
Multi-factor authentication, or a passkey where the service offers one.
Why it matters to you: Even a correctly guessed password stops at the door. This is the layer that makes the rest survivable.
C. A practical example: a password with a story behind it
Luca uses this for his webmail:
Liverpool1990
The team he supports, and the year he was born. It is meaningful, easy to recall, and it sits precisely where a dictionary attack looks first: popular team names combined with plausible years.
An old forum he had forgotten about is breached, and his address and password end up in a circulating list. From there it takes no guessing at all — the same combination is simply tried on other services.
- It opens his webmail.
- His social accounts follow, because the passwords there are variations of the same thing.
- Password resets on other services start arriving in a mailbox he no longer controls.
What would have changed the outcome
- A dedicated passphrase for email — something like lemon-train-7-faraway-sea — belonging to no list and to no other account.
- That passphrase stored in a password manager, which then generates different passwords everywhere else.
- Multi-factor authentication on the mailbox, so the leaked password would not have been enough.
Luca was not careless. He picked something he would remember — which is what almost everyone does, and exactly what the attack is built around.
About five minutes. Work with examples, not with your real passwords.
Step 1 — Sort these by risk
- Jessica90
- Rome2024!
- Blue!Dog$27Pasta
- summer123
- Book!Table-Cloud7
- For each: very high risk, medium, or low? Then ask what makes the difference — it is rarely the symbols.
Step 2 — Transform one, in your head
- Think of a weak password of your own. Do not write it down.
- Replace the obvious word with three or four unrelated ones.
- Add numbers that mean nothing — not a date you would recognise.
- Put a symbol somewhere other than the end.
- Then ask: would the new version turn up in a list built about me?
The honest test is not whether it looks complicated. It is whether someone who read your social profiles could assemble it.
E. Videos, articles and further resources
Independent and institutional sources in English.
NCSC (UK) — Three random words, or #thinkrandom
The clearest short piece on why unpredictability beats complexity — and how to get it without a system to remember.
https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0
CISA — Use strong passwords
Plain-language guidance on password length and on using a password manager.
https://www.cisa.gov/secure-our-world/use-strong-passwords
EFF — Creating strong passwords
A clear method for building a passphrase you can actually remember, including the dice-based approach.
https://ssd.eff.org/module/creating-strong-passwords
NIST — Digital Identity Guidelines, SP 800-63B (Revision 4)
The August 2025 standard behind most modern password advice. Technical, but this is where ‘length over complexity’ comes from.
https://pages.nist.gov/800-63-4/sp800-63b.html
NCSC (UK) — Password managers: how they help you secure passwords
A sober answer to the question most people ask first: is it safe to keep all my passwords in one place?
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers
NCSC (UK) — What to do if your account is hacked
Worth reading before you need it: what to do in the hours after an account stops being yours.
https://www.ncsc.gov.uk/section/respond-recover/hacked-accounts
Links checked in August 2026.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Awareness pillar at level FL2 and pairs closely with the brute force resource.
Skills
- Telling a predictable password from an unpredictable one, regardless of how it looks.
- Building passphrases that are not based on common words or personal details.
- Using a password manager and setting up a second factor on critical accounts.
For professionals and organizations
- Recognising dictionary attacks as a systemic risk to staff accounts, not an individual failing.
Awareness
- Recognising that convenient, meaningful passwords are the most targeted precisely because they are common.
- Understanding the link between reuse and what happens after somebody else’s breach.
For future instructors and ambassadors
- Being able to explain this without making anyone feel foolish. Nearly everyone has a password with a story behind it.
Secure Behavior
- Retiring weak passwords gradually, starting with the accounts that matter.
- Making a password manager part of the routine rather than an occasional effort.
- Checking periodically whether your addresses appear in known breaches.
For organizations
- Setting minimum policies on length, uniqueness, MFA and repeated-attempt blocking (R8).
G. Questions to sit with
- How many of your current passwords contain a word, a name, a date or a reference someone could find on your social profiles?
- If one of them were guessed, how many other accounts use the same thing, or a small variation of it?
- Do you already have at least one critical account protected by something that belongs to no list?
- Which account could you move out of reach before the end of today?
H. What to do now
The recommendations (R) and security measures (MS) that apply to both dictionary and brute force attacks.
Credentials
- R1 — Do not use the same, or nearly the same, password across your accounts.
- R2 — Use a reliable password manager with a strong and unique master password.
- R3 — Make your passwords or passphrases at least 16 characters, with numbers, upper and lower case letters and symbols.
- R4 — Turn on multi-factor authentication on your important accounts: email, main social accounts, financial services.
- MS1 — Use a generator rather than inventing passwords: it produces things no dictionary contains.
- MS2 — Let the manager fill them in, which also avoids the weak human variants people fall back on.
Around the credentials
- R6 — Keep your device software up to date: malware that steals or intercepts passwords does not care how strong they are.
- R8 — Turn on login attempt limits and alerts where the service offers them.
- MS4 — Use a long alphanumeric passcode on the device where your password manager is installed.
- MS17 — Give the email address linked to your financial services a unique, strong password and a second factor. It is usually the first account tried after a successful guess.
The minimum useful step
- Choose one critical account: email, bank or cloud storage.
- Give it a new passphrase that contains no word connected to you (R3, MS1).
- Stop reusing it anywhere else (R1), and store it in a password manager (R2, MS2).
- Turn on the second factor (R4, MS17).
That single account moves out of reach of both attack types at once — the guessing and the reuse.
In short
- Dictionary attacks try what people choose, not everything possible — which is why they are fast.
- Personal details are the weakest ingredient: they narrow the list rather than widening it.
- Unrelated words beat clever substitutions, and a generator beats both.
- Uniqueness is what limits the damage when the breach happens somewhere else entirely.
Related resources in this course
The neighbouring pieces of the same picture:
- Brute Force Attacks: How They Work and What Stops Them
- Password Strength: How to Create Secure Credentials
- The Power of Passphrases: How to Create a Passphrase You Will Remember
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply