3 ms·
https://xkcd.com/936/ https://xkcd.com/936/
by rip747 12y ago
https://xkcd.com/936/ https://xkcd.com/936/
- phreeza 12y agoMy immediate thought as well. I liked his way of getting special chars into the mix, as required in many systems, with margretthatcheris100%SEXY
- mfoy_ 12y agoAlso, if you went with something like "Margret Thatcher is 110% sexy" then you've got even more characters, even more entropy, and even more special characters and it's even more natural to type out.
- JshWright 12y agoI'd wager better than half of the sites you use on a regular basis (and especially sites like your bank's) would not accept a password that long.
- anonbanker 12y agoNote that bruce schneirer said not to do it, so people don't. nobody's proved it wrong, but BS said not to, so people avoid it.
- Dylan16807 12y agoPeople are really bad at estimating password security, which is why he advised against it as a trick. You're right that he shouldn't have advised against it on a basic entropy level... except that 44 bits is not enough. Using words is okay, but you have to impress on people two critical things. 1. random words. not sentences. use a program or dice. 2. Each word is only as good as two random characters. 8 words is as good as 16 characters, no more. People try to get 'clever' and it never works out well.
- codeulike 12y agohttp://preshing.com/20110811/xkcd-password-generator/ http://preshing.com/20110811/xkcd-password-generator/