For about five months, a browser extension sat quietly on the home computers of 154 people and watched them log in.
The researchers never saw a password. Everything was hashed on the machine before it went anywhere, leaving them with the shape of each one: its length, its mix of characters, the site it was typed into, and whether the same string had appeared before.
Very often, it had.
What 154 people actually typed
Sarah Pearman and her co-authors at Carnegie Mellon University presented the results at a 2017 computer security conference, having followed each participant for an average of 147 days. Those people logged in across 26 web domains apiece and covered the lot with fewer than 10 distinct passwords.
Roughly 60 per cent of those distinct passwords were recycled, either typed identically on another site or built around a chunk of four or more characters lifted from one the same person used elsewhere.
Banking got no special treatment. Around 85 per cent of the passwords on financial sites appeared elsewhere too, and nearly all of that crossover ran into unrelated categories, so the login for a savings account was also the login for a shoe shop.
What partial reuse looks like up close
Mostly it looks like adding a character.
Among passwords that shared a substring with another, the most common gap between the two was a single character. Digits were the strongest predictor in the Carnegie Mellon model, multiplying the odds of reuse by more than twelve. The authors’ own explanation is that a password with a number in it satisfies more websites’ fussy signup rules, so it travels further.
The tidy minority had barely any accounts
Ten participants mostly built something new for each site, which sounds like a win for good habits until you look at what they were doing online. With one exception, every one of them entered passwords on eight domains or fewer, and they were active on their computers on only 17 per cent of the days they spent enrolled.
The heavy users went the other way. Ninety-four participants, the largest cluster by far, both copied passwords outright and modified them, and they averaged 32 online accounts each. Discipline held up fine at eight accounts and collapsed at thirty.
The password manager result, with a handbrake
Only 19 of the 154 participants had a password manager installed, and the study found no measurable effect on either reuse or strength.
That result deserves caution. One paper is one paper, the subgroup is tiny, and the software could not tell whether people were generating random strings or merely parking passwords they had invented themselves. Rick Wash and colleagues at Michigan State University, who watched 134 participants over six weeks, found each password being reused on 1.7 to 3.4 websites. Their study did not measure partial reuse at all, so the higher figure out of Pittsburgh partly reflects counting a habit nobody had counted before.
Why a recycled password is worth money
Somewhere there is a text file with an old forum password in it, sitting in a folder alongside a few hundred million others. Troy Hunt, the Australian security researcher behind the breach notification service Have I Been Pwned, has documented the trade in combo lists, which are exactly that: vast dumps of email and password pairs scraped out of past breaches. Cheap automated tools fire them at unrelated websites until one opens. Defending against it is awkward, because a successful run looks identical to a customer logging in correctly.
One shared string, and the breach at a defunct hobby forum becomes a problem at an email provider.
The rules that encouraged this have been withdrawn
In 2025, the US National Institute of Standards and Technology finalised revision 4 of its digital identity guidelines, and the password section reads like a quiet apology. Websites must stop demanding mixtures of character types, and they must stop forcing periodic changes unless there is evidence of compromise. Password managers and autofill have to be allowed, and every new password gets checked against blocklists of strings already known to have leaked.
Each of those requirements targets the behaviour the extension recorded: a handful of memorable strings, nudged sideways by a digit, stretched across an entire online life.
The standard now assumes a machine is doing the remembering. Anyone who ever stuck a “1” on the end to get past a signup form was just covering the shift until it arrived.