@R_Connelie@... Some more tips:
PASSWORDS MUST NOT BE GUESSABLE! I repeat, NOBODY must EVER be able to guess it! "I think it's safe" is NOT enough, you must KNOW that nobody can figure it out!
Always use passwords longer than 12 characters! Random 8 character passwords can already be cracked by botnets of moderate size today at a fairly high rate, and even 12 character passwords will be in trouble soon. But for most not-so-sensitive things, 12 characters are safe enough. But I always go for 20 characters nowadays for new passwords. Password length is king!
Go ahead and make sentences if you want. But NEVER EVER AT ALL use any existing phrase or saying. ANYTHING THAT EVER HAS BEEN SPOKEN OR WRITTEN are likely to be in *some* database somewhere or be found by a persistant attacker (somebody might try every phrase in your diaries), and is INSECURE.
Make it as random as possible. Going for phrases? Screw up the grammar, intentionally. Use misspellings. Make them sound strange. Make it sound like Yoda. MIX LANGUAGES! Know several languages? Use it to your advantage! And better yet, use other languages too that are close to the ones you know and mix words from them in, because you'll remember those.
Don't shorten them down. If you've got a good sentence, DO NOT SHORTEN IT! Do NOT turn something like "the moon is blue and crazy" to "tmibac", because that's "lossy compression" and thus *throws away* data that an attacker otherwise would have to get correct. With the shorter password, he only need the first characters right while he otherwise would need to get everything right. Because the attacker could also guess for the mouse is boxed and cool" and he'd get the same shortened password, which proves that it's a bad idea (he don't need to make a correct guess, only a good-enough guess).
Bad passwords - and why:
l33tsp33k - short and easy to guess
password - the first an attacker will test
youcan'ttouchthis - well known phrase
Good passwords:
this r4ndom Be, a MUCH ranDOm - Strange grammar, more then 5 words, letters are NOT consistently replaced with numbers, not a known phrase, upper and lower case mixed
cant cant cant be gueeeeesed cant be guessed - Is repetition really bad? Only if the attacker *knows* you're using repetition. Otherwise he won't know if the first three words are unique or identical, and so he must try all possibilities.
crackelyCkrackety KRACK thIS - now we're making up words.
This lsenord is very mycket sfert - mixing languages (swedish and english) and even mixes up words ("skert" and "safe") (edit: Crap, ZDNet don't allow those extra swedish characters...)