Explicitly mention to use no less than 4 words when making a random passphrase, in the Intro to Passwords article

Maybe you could also mention StrongPhrase.net when suggesting ways to generate random passphrases?

Seems pretty uncontroversial to mark this as approved and accepting PRs :+1:

I don’t know about recommending a specific password generator necessarily, but I think that warrants its own separate discussion.

3 Likes

Not really sure what is the benefit. Just use your password manager for this.

1 Like

I should make a new topic asking about StrongPhrase, but here are some of the strengths it has compared to most other password generators

Today was my first time seeing StrongPhrase.net, and the concept is great.

With that being said, I disagree with allowing a third-party to provide or even recommend passphrases. For example, clearnet users could have their IP address logged with a list of passphrases they were shown or copied from the page.

Even as a Tor user, I do not believe that is a good practice.

1 Like

Password managers have option to capitalize words, add numbers and special characters, so even a 3-word pass can be a bit stronger. But yes, 4 words should be recommended as a minimum. Problem is, there are services that limit passwords to 20 characters, and it’s almost impossible to have good passphrase in that case.

And I see passkeys are mentioned 8 times in that text, and 2FA only once, which tells me someone has a horse in this race :slight_smile: