A tech columnist (Manjoo, maybe? I can’t remember) endorsed this XKCD cartoon in a tweet. xkcd: Password Strength
The gist of it is that a string of random but memorable words is a better password than a short word and a few numerals. So in the cartoonist’s example, “correct horse battery staple” is a much better password than Tr0ub4dor&3.
Do any computer security experts want to weigh in on this?
I always thought we were encouraged to use something short and sweet for a reason. No?
If the cartoonist is on to something, then that makes me wonder whether the words need to be truly random. For the sake of memorability, could I achieve the same security with words picked from some famous source. For instance, would “not what your country can” from JFK’s inauguration speech be sufficiently random?
Any other suggestions for passwords that are both secure and easy to remember?