I like to write out my 16+ password on paper using random characters that come into my head.
Then I put that random password into the appropriate section during the setting up of the account. Makes me realize how effective them asking you to type your password out twice really is.
Why does anyone use entropy yielded from machine brains? There's no one out there that's gunna guess a combination of 16+ characters that came to YOUR mind RANDOMLY.
Then again, I'm new so I'm probs wrong.
In some very rare situations, you may be right. Machine generated random passwords are not necessarily always safe. You never know how random random can be. You can click Generate and it can bring you a sequence of 16 identical characters. But then you have a brain and can see patterns, so if you see a pattern you skip the newly generated password and re-generate until you get one random enough.
I would argue coming up with your own password is a decision as bad as generating a Brain Wallet always was. Your brain sees patterns and I think most of the things we are doing are actually patterns too. This makes me believe we are even thinking in patterns too.
I tried coming up with random passwords out of my mind too. While at a first glance they seemed random, I soon realized there were a few things that went wrong. First of all, I realized that I was only mainly using less than half of the alphabet in my 'random generation' of passwords. Then I realized many of the sequences came from actual words. I would have 'S' coming up first in my mind, write it down, then I would think of '@', write it down next to the 'S' and then, involuntarily, I would think of 'd' as the next character.
That leaves me with the sequence 'S@d', which I could transform into 'Sad' from the English vocabulary.
But then I realized I was doing this not so random generation. Which led to the great idea of moving forward to using an actually randomly generated password. You can do this in so many ways if you do not want to rely on machines. The even bigger problem is that if we popularize this idea of 'you can produce your own password randomly', there will be many who will fail and will end up having passwords like tH1si$aGo0Dp@s$w0RD which is obviously not a good and secure choice.
-
Regards,
PrivacyG