Exactly what I came here to say @joernsmock. Long strings of random characters are no harder for computers to guess than equally long strings made up of dictionary words. Epecially obscure or non-English words.

Claiming they are is a sales pitch for password managers vendors, not a security fact. Current passphrase advice reflects that XKCD comic, and suggests passphrases be long, memorable, and changed as infrequently as possible.

#PasswordManagers #passphrases

to be extra secure, consider including a newline, null byte, or bell character in your password or passphrase

#infosec #passwords #passphrases #securityTips

Just had the interesting thought occur to me that I'd like #autocorrect in my passwords and that's not actually insane?

I use #passphrases everywhere and I think everyone should.

Sometimes however, I typo somewhere while typing the dozens of characters; requiring me to type the entire thing again.

However, words are the source of entropy in my passphrases, not their characters.

Therefore, correcting any word that is not on the word list to the closest word that is would not diminish entropy.

In this week's ADMIN Update newsletter, Mark Heitbrink offers recommendations for team-capable password management
https://www.admin-magazine.com/Archive/2025/86/Passwords-passphrases-and-passkeys?utm_source=mam
#password #security #passphrases #passkeys #standards #guidelines

It’s concerning how many people try to memorize #passwords like pX#7k!g and believe they’re safe.

That’s just way too few characters, and memorising is already almost impossible.

Instead of passwords, we should use #passphrases. They are easier to remember and, thanks to their greater length, significantly more secure – even if an attacker knows the list of words from which the phrase was constructed.

Passsatz can help with the creation. https://apps.apple.com/ch/app/passsatz/id6698877095

‎Passsatz

‎Passwörter. Wer mag sie schon? Aber so lange wir mit ihnen leben müssen, sollen sie leicht merkbar und trotzdem sicher sein. Passsatz erzeugt zufällige und sichere Passsätze, aber auch klassische Passwörter, da einige Dienste diese immer noch verlangen. Leider. Lies mehr zum Thema Passsätze und Pa…

App Store
I just published “Generating Passphrases Like correct horse battery staple” at
https://www.ii.com/passphrase-generators/ - please post suggestions for passphrase generators as a reply to this toot and I'll include them in my article!
#InfiniteInk #Privacy #Security #Tech #Passwords #Passphrases #CorrectHorseBatteryStaple
#Words #Writing #Byℵ #ByNM
ii.com: Generating Passphrases Like correct horse battery staple

Infinite Ink

@gabe_sky
Great idea, thanks! Bookmarked.

As chance would have it, I also built another useful thing, way back in 2015:

https://batterystaple.pw/ - generates secure #Passphrases entirely in your browser

Like you, I built it because I was not happy with the existing alternatives. Since then, I have been using it quite regularly, but I have no idea if anybody else uses it (nor a way to find out).

In any case, I will gladly continue to pay for the domain name!

battery staple

Use strong, unique passphrases.
Passphrases are easier to remember and harder to crack.
#Passphrases #PasswordStrength #Authentication
@evangreer @fightforthefuture.org @bsky.app @guardianproject @internetarchive @torproject @signalapp @session @simplex @freedomofpress @eff @privacysafe
🔐 #PrivacySafe Bot: Strong #passwords made simple.
Whether you’re setting up devices and user access ahead of time or recovering from a breach, get cryptographically strong passwords & #passphrases — right in your browser, on your device, never stored on a server.
https://bitsontape.com/p/password-bot-security
🤩 Announcing: PrivacySafe Bot - Easily Create Secure Passwords

PrivacySafe Bot is the latest of our privacy tools to add to your belt

Bits On Tape