In this work, we make a substantial step forward towards understanding the distribution of passwords. By introducing a number of computational statistical techniques and based on fourteen large-scale datasets, which consist of 113.3 million real-world passwords, we for the first time show that Zipf's law natively exists in the popular (and thus vulnerable) part of human-generated password datasets. Further, we provide compelling evidence that this law is also highly likely to hold in the remaining part of human-generated passwords. (see more in our IEEE TIFS'17 paper; and its applications in ESORICS'16 paper)