A poll, aimed in particular at people who think they understand the technologies around password cracking. Assume that there is at least one password that you need to be strong and need to remember & type not-infrequently. How many characters is enough for you to feel comfortable in 2024? Assume any char you can type easily is available.
[May need a follow-up poll if the majority is at >=12]
[Boost if you’re interested in the result]

#infosec

9
3.3%
10
6.2%
11
2.2%
>=12
88.3%
Poll ended at .

@timbray I thought I read a few years back that a desktop GPU can brute force passwords up to 14 characters in length.

A "master password" should probably be a sentence these days.

@chadgeidel @timbray

Mine is over 2 dozen characters. It's a 3-word phrase that is complete nonsense, but comes from a joke comic strip that several of us in the office laughed our asses off about in 2002 or so.

So those 3 words, plus the 3 parts of a phone number that I've got memorized from my childhood in the '60s.

AREACODEwordEXCHANGEwordLAST4DIGITSword

I've never struggled to remember or type it. You couldn't guess it even if you know me very well.