3 ms·
While I agree with you, in my experience it's important for the security answers to be pronunceable. Otherwise some CS will just wave them away as being gibberi
by sersi 2y ago
While I agree with you, in my experience it's important for the security answers to be pronunceable. Otherwise some CS will just wave them away as being gibberish.
So I generate random answers but them modify it so that it's somewhat pronunceable.
Also obviously don't use the actual password since they are stored in plaintext
- tasuki 2y agoI'm also a fan of pronounceable passwords - I even have a script to generate them,[0] yes it decreases entropy a little. I don't store passwords on my phone, so I sometimes find myself retyping passwords, and I find these much easier to retype. [0]: https://github.com/tasuki/dotrc/blob/master/.bin/pronounceable https://github.com/tasuki/dotrc/blob/master/.bin/pronounceab...
- alwayslikethis 2y agoPronounceable passwords is what pwgen does. You might be surprised by how much entropy you lose, which is apparently around half: https://security.stackexchange.com/questions/72781/security-of-pronounceable-passwords https://security.stackexchange.com/questions/72781/security-...