Passwords have been a hot topic lately in Finland, after someone revealed Finnish emails and passwords by the thousands. Now, specialists of all kinds are rushing to give good advice on how to keep our private online properties private. Time after time these specialists keeps telling us to use numbers and special characters in addition to normal letters – and at the same time admit that these passwords are very hard to remember.
The latests example was from today’s Taloussanomat, where online security company Tectia’s founder and CEO Tatu Ylönen told the journal (freely translated): “a good password is at least 8 characters, and consists of as many capital and normal letters, as well as one or two special characters. The password shouldn’t be a known word.” Mixing capital and non-capital letters with special characters in an order that is not a word is indeed very hard to remember, especially if you keep changing it periodically. To make things worse 8-10 character passwords are also relatively easy to break.
What to do then? As a solution, the specialists are saying we should use external sources in addition to passwords, for example SMS or key word sheets. I say this is good for online banking, but way too complicated for daily email use, not to mention social media services.
But wait, there is an easier solution – lets make passwords considerably longer yet easier to remember (click to enlarge):
I especially like the end quote of the cartoon: “Through 20 years of effort, we’ve successfully trained everyone to use passwords that are hard for humans to remember, but easy for computers to guess.”

This idea seems to be accurate although counter intuitive. Do you have any more facts to back this claim? Can’t really rely on one cartoon, don’t you think
By: Aarne on November 28, 2011
at 12:47 pm
You’re right, a cartoon might not be that reliable, but it’s basically about the how many bits of entropy the password has.
Here’s more on password entropy: http://en.wikipedia.org/wiki/Password_strength
By: Sami Salmenkivi on November 28, 2011
at 2:24 pm
What I understood by reading about password entropy is exactly what the cartoon claimed it to be. Human generated passwords which makes sense sort of speak like the “correcthorsebatterystable” are very strong when they are long enough. About 20 Latin case insensitive letters would do. 20 letters would create about 36 bits of entropy.
The thing that made me wonder is are you able to use this many characters in regular web service?
By: Aarne on November 28, 2011
at 7:11 pm