Hacker News new | ask | show | jobs
by mjochim 1217 days ago
1. Make it long. 2. That's it.

I wouldn't want to claim that one ideal set exists. But this one comes close. There is an often-cited XKCD comic that illustrates this: concatenating random lexicon words into a long, letter-only password (no special characters needed at all) is usually a very good password strategy.

https://xkcd.com/936/

Anything beyond that, in terms of better IT security, does not involve better passwords, but rather e.g. 2FA, Hardware tokens.