xkcd's Password strength? Iffy

xkcd password generator

The xkcd comic on password strength is wrong about one thing: it may seem easy to remember 4 random words, but it's trickier in practice. I got two-factor authentication setup on my Google logins, but Facebook Philippines still doesn't have two-factor auth, so I did the 4-word bit. Coming back to it now to check recall, I knew the 4 words but couldn't remember in what order they went in. Had to look it up in Firefox's saved passwords.

Looking at 4 randomly generated words can be beguiling though, like story prompts, like Tarot.

