The archive
Issue #013
Security Horror Stories 6 min read· 25 Aug 2026

The admin123 Incident

A seething client demands answers about his 'hacked' account. We check everything—2FA, encryption, SSL, logs. Nothing. Then we ask for his password. It's 'admin123.' He disabled 2FA because it was 'too long.' The disappointment was palpable.

Share
CTO takeaway

The lesson, minus the scar tissue.

  • The most expensive security vulnerability is always the user who thinks they're not important enough to be hacked.
  • 2FA isn't optional. It's mandatory. If the client disables it, document it. In writing. With a signature.
  • Never let a client's password be 'admin123.' Force password complexity. Force 2FA. Force common sense.
  • When a client blames you for 'hacking,' check the most obvious thing first: the user's own behavior.
  • Security is only as strong as the weakest link. That link is usually the person with the password.
Never miss an issue

Get the next Chronicle in your inbox.

A comic, a story and a takeaway every other week. Written for founders who inherited a codebase they didn't choose.

Free forever. Unsubscribe in one click.

Related Chronicles.