Better password practices:
- Use Linux. I’m only half-kidding. A Linux distro will have you typing your password in far more than you ever thought you should have to, giving you much more practice with password memorization.
- Chunk the passwords, like phone numbers. am!z - _hBg - kj47 - GEW is easier to memorize than am!z_hBgkj47GEW.
- Use a password manager.
- Use a password manager.
Or learn your passwords like our ancestors did. If something strikes you as poetic use it as a long password. I still remember an XKCD with “Correct Horse Battery Staple”.
I don’t know where the entropy is at these days so I’m not sure exactly how many words are recommended at this point, but the issue with passphrases is that you have to treat each word like it’s one character. Instead of a lot of symbols, now you need a lot of words for a strong passphrase. It also has to be random assortments of words that make no sense, so passages out of any documents are not a good idea. That XKCD strip is definitely outdated because 4 words wasn’t enough even 10 years ago.
That’s only true if someone guessing your pass phrase knows that it’s made up of words and not random characters.
The idea behind pass phrases is that these things are easy for your human brain to remember, but long enough to be hard to guess by typing random characters (or even combinations of words) by an attacker or a computer (or even a LLM)
Or a person just includes passphrase cracking tools on the database they’re working on.
Ever since the humble space has been supported in passwords, it’s become so easy to remember them. The longest password I had ever used was “A future is not given to you. It is something you must take for yourself.” At a hotel chain I did IT for a decade ago. The chain is shuttered and gone, and I still remember my password.
I have been extremely irritated in past places requiring short passwords that are also constantly changing every few months. The annoyance is exactly why people just start using “august2025!!” type passwords.
Just let me have a monstrously long password and don’t make me change it without a good reason.
The reason those passwords need to change often is because of dumb people who give their personal password to others.
At least then their accounts aren’t compromised and being used by the wrong people for more than 1-3 months.
So please, don’t blame the IT for the actions of dumb users.



