Hacker News new | ask | show | jobs
by s_gourichon 3018 days ago
Those pushed into FUD against XKCD password scheme can simply add more words. All arguments in https://www.explainxkcd.com/wiki/index.php/936:_Password_Str... remain, including the ease of remembering.

You still definitely have to accept at least four words actually randomly generated (this is important, else the scheme falls apart horribly). Accepting 6 random words is pretty secure IMHO.