Bruce Schneier today posted a fascinating (and, in a way, sad) analysis of passwords gleaned from a MySpace phishing attack:
We used to quip that "password" is the most common password. Now it's "password1." Who said users haven't learned anything about security?
But seriously, passwords are getting better. I'm impressed that less than 4 percent were dictionary words and that the great majority were at least alphanumeric. Writing in 1989, Daniel Klein was able to crack (.gz) 24 percent of his sample passwords with a small dictionary of just 63,000 words, and found that the average password was 6.4 characters long.
If you want to be as secure as possible, however, you should check out Schneier's own Password Safe (free download). I swear by it.