## # Introduction
<p><img src="https://i.imgur.com/kjWF1So.jpg" alt="Different characters on a computer screen"></p>
<p>According to a 2019 <a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/PasswordCheckup-HarrisPoll-InfographicFINAL.pdf">Google / Harris Poll</a>, 24% of Americans have used common passwords, like <code>abc123</code>, <code>Password</code>, and <code>Admin</code>. Even more concerning, 59% of Americans have incorporated personal information, such as their name or birthday, into their password. This makes it unsurprising that 4 in 10 Americans have had their personal information compromised online. Passwords with commonly used phrases and personal information makes cracking a password drastically easier.</p>
<p>You may have noticed over the years that password requirements have increased in complexity, including recommendations to change your passwords every couple of months. Compiled from industry recommendations, below is a list of passwords requirements you will be asked to test: </p>
<p><strong>Password Requirments:</strong></p>
<ol>
<li>Must be at least 10 characters in length</li>
<li>Must contain at least:<ul>
<li>one lower case letter </li>
<li>one upper case letter </li>
<li>one numeric character </li>
<li>one non-alphanumeric character</li></ul></li>
<li>Must not contain the phrase <code>password</code> (case insensitive)</li>
<li>Must not contain the user's first or last name, e.g., if the user's name is <code>John Smith</code>, then <code>SmItH876!</code> is not a valid password.</li>
</ol>
<p>Here is the dataset that you will investigate this project:</p>
<div style="background-color: #ebf4f7; color: #595959; text-align:left; vertical-align: middle; padding: 15px 25px 15px 25px; line-height: 1.6;">
    <div style="font-size:20px"><b>datasets/logins.csv</b></div>
Each row represents a login credential. There are no missing values and you can consider the dataset "clean".
<ul>
    <li><b>id:</b> the user's unique ID.</li>
    <li><b>username:</b> the username with the format {firstname}.{lastname}.</li>
    <li><b>password:</b> the password that may or may not meet the requirements. <i>Note, passwords should never be saved in plaintext, always encrypt them when working with real live passwords!</i></li>
</ul>
</div>
<p>Warning: This dataset contains some <strong>real</strong> passwords leaked from <strong>real</strong> websites. These passwords have been filtered, but may still include words that are explicit and offensive.</p>
<p>From here on out, it will be your task to explore and manipulate the existing data until you can answer the two questions described in the instructions panel. Feel free to import as many packages as you need to complete your task, and add cells as necessary. Finally, remember that you are only tested on your answer, not on the methods you use to arrive at the answer!</p>
<p><strong>Note:</strong> To complete this project, you need to know how to manipulate strings in pandas DataFrames and be familiar with regular expressions. Before starting this project we recommend that you have completed the following courses: <a href="https://learn.datacamp.com/courses/data-cleaning-in-python">Data Cleaning in Python</a> and <a href="https://learn.datacamp.com/courses/regular-expressions-in-python">Regular Expressions in Python</a>.</p>

In [32]:
import pandas as pd

In [33]:
logins = pd.read_csv("logins.csv")

In [34]:
logins.info()

<class 'pandas.core.frame.DataFrame'>
RangeIndex: 982 entries, 0 to 981
Data columns (total 3 columns):
 #   Column    Non-Null Count  Dtype 
---  ------    --------------  ----- 
 0   id        982 non-null    int64 
 1   username  982 non-null    object
 2   password  982 non-null    object
dtypes: int64(1), object(2)
memory usage: 23.1+ KB


In [35]:
logins.head(10)

Unnamed: 0,id,username,password
0,1,vance.jennings,vanceRules888!
1,2,consuelo.eaton,Mail_Pen%Scarlets.414
2,3,mitchel.perkins,Z00+1960
3,4,odessa.vaughan,D-rockyou
4,5,araceli.wilder,Araceli}r3
5,6,shawn.harrington,126_239_123
6,7,evelyn.gay,`4:&iAt$'o~(
7,8,noreen.hale,25941829163
8,9,gladys.ward,=Wj1`i)xYYZ
9,10,brant.zimmerman,L?4)OSB$r


Going through each row -> Boolean Indexing

In [36]:
# Rule 1: Must be at least 10 charachters

lenght_check = logins['password'].str.len() >= 10
lenght_check.head(10)

0     True
1     True
2    False
3    False
4     True
5     True
6     True
7     True
8     True
9    False
Name: password, dtype: bool

In [37]:
valid_pws = logins[lenght_check]
valid_pws.head(10)

Unnamed: 0,id,username,password
0,1,vance.jennings,vanceRules888!
1,2,consuelo.eaton,Mail_Pen%Scarlets.414
4,5,araceli.wilder,Araceli}r3
5,6,shawn.harrington,126_239_123
6,7,evelyn.gay,`4:&iAt$'o~(
7,8,noreen.hale,25941829163
8,9,gladys.ward,=Wj1`i)xYYZ
10,11,leanna.abbott,"@_2.#,%~>~&+"
11,12,milford.hubbard,Milford<3Tom
12,13,mamie.fox,chichi821?


In [38]:
bad_pws = logins[~lenght_check]
bad_pws.head(10)

Unnamed: 0,id,username,password
2,3,mitchel.perkins,Z00+1960
3,4,odessa.vaughan,D-rockyou
9,10,brant.zimmerman,L?4)OSB$r
16,17,domingo.dyer,VeOw{*p
17,18,martin.pacheco,MP1985???
18,19,shelby.massey,787175
19,20,rosella.barrett,TOBBY05
25,26,dianna.munoz,munoZ_001
26,27,julia.savage,"z5dm_c""R\"
27,28,loretta.bass,%%%bass


In [39]:
bad_pws.shape[0], valid_pws.shape[0]

(422, 560)

In [40]:
# Rule 2: One uppercase, One lowercase, One Numberic, One non-alphanumeric (special) AT LEAST

lcase = valid_pws["password"].str.contains("[a-z]")
ucase = valid_pws["password"].str.contains("[A-Z]")
numeric = valid_pws["password"].str.contains("\d")
special = valid_pws["password"].str.contains("\w")

pd.concat([valid_pws, lcase, ucase, numeric, special], axis=1)

Unnamed: 0,id,username,password,password.1,password.2,password.3,password.4
0,1,vance.jennings,vanceRules888!,True,True,True,True
1,2,consuelo.eaton,Mail_Pen%Scarlets.414,True,True,True,True
4,5,araceli.wilder,Araceli}r3,True,True,True,True
5,6,shawn.harrington,126_239_123,False,False,True,True
6,7,evelyn.gay,`4:&iAt$'o~(,True,True,True,True
...,...,...,...,...,...,...,...
975,976,freeman.rose,cHw2Leth5JXY,True,True,True,True
976,977,monica.flores,*;~a8dq5%s',True,False,True,True
978,979,miriam.haynes,Gizzard.Muse+Patters_857,True,True,True,True
979,980,genaro.russo,Rm3OwUfobjYxq,True,True,True,True


In [41]:
char_check = lcase & ucase & numeric & special

bad_pws = bad_pws.append(valid_pws[~char_check], ignore_index=True)
valid_pws = valid_pws[char_check]

bad_pws.shape[0], valid_pws.shape[0]

(610, 372)

In [42]:
# Rule 3: Must not contain the phrase "password" (case insensitive)

banned_phrases = valid_pws["password"].str.contains("password", case=False)

bad_pws = bad_pws.append(valid_pws[banned_phrases], ignore_index=True)
valid_pws = valid_pws[~banned_phrases]

bad_pws.shape[0], valid_pws.shape[0]

(611, 371)

In [43]:
# Rule 4: Must not contain the user's first or last name

valid_pws["first_name"] = valid_pws["username"].str.extract("(^[a-z]+)", expand = False)
valid_pws["last_name"] = valid_pws["username"].str.extract("([a-z]+$)")

valid_pws.head()

Unnamed: 0,id,username,password,first_name,last_name
0,1,vance.jennings,vanceRules888!,vance,jennings
1,2,consuelo.eaton,Mail_Pen%Scarlets.414,consuelo,eaton
4,5,araceli.wilder,Araceli}r3,araceli,wilder
6,7,evelyn.gay,`4:&iAt$'o~(,evelyn,gay
8,9,gladys.ward,=Wj1`i)xYYZ,gladys,ward


In [44]:
for i, row in valid_pws.iterrows():
    if row.first_name in row.password.lower() or row.last_name in row.password.lower():
        print(row)
        valid_pws = valid_pws.drop(index=i)
        bad_pws = bad_pws.append(row, ignore_index=True)

id                         1
username      vance.jennings
password      vanceRules888!
first_name             vance
last_name           jennings
Name: 0, dtype: object
id                         5
username      araceli.wilder
password          Araceli}r3
first_name           araceli
last_name             wilder
Name: 4, dtype: object
id                         12
username      milford.hubbard
password         Milford<3Tom
first_name            milford
last_name             hubbard
Name: 11, dtype: object
id                        141
username        ronald.brooks
password      P1G_bT”_zBrooks
first_name             ronald
last_name              brooks
Name: 140, dtype: object
id                       150
username      raymundo.haley
password      HaleyComet333$
first_name          raymundo
last_name              haley
Name: 149, dtype: object
id                        511
username           kyle.colon
password      941Colonwashere
first_name               kyle
last_name               c

In [45]:
# So, we have gone through the four rules now!

valid_pws.head()

Unnamed: 0,id,username,password,first_name,last_name
1,2,consuelo.eaton,Mail_Pen%Scarlets.414,consuelo,eaton
6,7,evelyn.gay,`4:&iAt$'o~(,evelyn,gay
8,9,gladys.ward,=Wj1`i)xYYZ,gladys,ward
13,14,jamie.cochran,Deviants.Assists.Impede+24,jamie,cochran
15,16,lorrie.gay,Q0G:[@u9*_`_,lorrie,gay


In [46]:
bad_pws.head()

Unnamed: 0,id,username,password,first_name,last_name
0,3,mitchel.perkins,Z00+1960,,
1,4,odessa.vaughan,D-rockyou,,
2,10,brant.zimmerman,L?4)OSB$r,,
3,17,domingo.dyer,VeOw{*p,,
4,18,martin.pacheco,MP1985???,,


# Q1: What Percentage of users have bad (invalid) passwords?

In [47]:
bad_pass = round(bad_pws.shape[0]/logins.shape[0], 2)
bad_pass

0.64

### Answer: 64%

# Q2: Which users need to change their passwords?

In [48]:
email_list = bad_pws["username"].sort_values()
print(email_list)

405       abdul.rowland
309        addie.cherry
372        adele.moreno
485        adeline.bush
279         adolfo.kane
             ...       
373    yvette.whitfield
232        yvonne.munoz
264        zachary.huff
172        zelma.abbott
49        zelma.rosario
Name: username, Length: 624, dtype: object
