Every time I read a password recommendation or policy, I get frustrated. It is always about their length and complexity, and they miss the real issue with passwords and how they get compromised.
So I wrote this small (non technical) paper on my thoughts on passwords and how I define a good password: http://dcid.me/texts/good-passwords.
Comments are welcome.
Hi Daniel:
Your thoughts make a lot of sense; too often, passwords are used for more than one device / application / venue, and are in the process made weaker as such.
http://www.dynamicnet.net/2012/03/weak-passwords-open-doors/ are thoughts I recently shared based on a pictorial someone shared with me in a LinkedIn WordPress group.
Thank you.