You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何经过SHA1哈希处理的密码最常见前缀为"00000"?

Why is "00000" the most common SHA1 prefix in Pwned Passwords?

Great question! Let's break down this phenomenon step by step:

  • Weak password dominance drives hash concentration
    The vast majority of passwords in data breaches are predictable, low-entropy weak passwords—think things like 123456, password, qwerty, or variations with simple substitutions. Many of these extremely common passwords happen to have SHA1 hashes starting with 00000. Since millions of people reuse these same weak passwords, their corresponding hashes (and their prefixes) show up far more frequently than others in the Pwned Passwords database.

  • Non-uniform hash distribution from non-random input
    While SHA1 is designed to produce uniformly distributed hashes when given random input, real-world passwords are anything but random. People tend to pick passwords that are easy to remember, which creates a skewed input set. This skew translates to non-uniform hash prefixes, and 00000 ends up being the most common simply because the most widely reused weak passwords cluster under this prefix.

  • Pwned Passwords' counting amplifies the effect
    Pwned Passwords doesn't just store unique hashes—it tracks how many times each hash has appeared in breaches. So if a single weak password with a 00000 prefix has been leaked 500,000 times, that prefix's "popularity" gets amplified by that count, making it stand out even more compared to prefixes associated with less frequently used passwords.

It's important to note that this isn't a flaw in SHA1 itself; it's a direct result of human behavior around password choice. The 00000 prefix is just a symptom of how many people rely on dangerously weak passwords.

内容的提问来源于stack exchange,提问作者lmcarreiro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:41:47