Is 1234 Your Password?

Bruce Schneier blogged about 2.5% of all passwords start with 1234 from a big sample of database. I know how common bad passwords are -- plenty of them in the web apps we have deployed (though they are all hashed when stored in DB). I also remembered running Johnny the Ripper over all CS1021 accounts almost 10 years ago, when they were not using shadow nor md5 hash back then. It was "easy" to get a new shell account back then :) Now I always use randomly generated password when signing up sites.