The most secure password
mostsecure.pw
mostsecure.pw
For the more ethically inclined amongst us the best course of action is probably to add this 'password' to some of the lists of common passwords out there, to help password strength utilities to filter it out on the level of 'correct horse battery staple' — an excellent password in itself, but used as an oft quoted example and thus not suitable for actual use.
The joke is it's the same every time.
Or just don't and leave it as a joke the way it is, I think we're over-engineering this.
That being said there's an actual password generator "feature" in duckduckgo for some reason: https://duckduckgo.com/?q=!password&t=ffab&ia=answer
I can't really imagine why anybody would want to use that though...
Bonus points to only have the password below-the-fold so that those who aren't going to read the explanation will be less likely to copy, paste, and carry on.
Ideally, as mentioned in an earlier comment, the password could be seeded through the browser's fingerprint to allow the joke to remain (it'll be the same password upon refreshing) but still won't be as damaging for those who don't get the joke (it's still not cryptographically secure).
And it gets a grade of A.
So that is definitely the password I'm going to use from now on!
Oh, and here's a useful function:
/* Returns a random integer that was determined by a fair roll of a dice. */
function randomInt() { return 4; }
The general principle is that humor does not scale. With enough users, the probability that a joke will be misinterpreted approaches 1.
I'm reminded of Al Franken's latest book where he talks about having to run what he says through the DeHumorizer now that he's a politician.
But then I thought about the users who don't know any better and might stumble onto this site. They aren't stupid. They just don't know any better, and a lot of education attempts can go over their heads. Worse yet, sites with poor password policies (seemingly every online banking site in existence, workplaces, sites with 16 character maximums, etc.) reinforce bad practices in their minds, while attempts at explaining the problems are forgotten. I'd probably explicitly note that it's a joke, especially if someone tries to copy the password. :)
If it is a joke, then they need something to indicate that, and very blatantly at that. Because there's a great deal of people who'd see that and not give it a second thought to use it.
There's a few PW generators which run on the client only and don't send any requests to third parties, and I use them sometimes. They are typically very JS heavy and use different seeds to generate sufficient entropy, like client fingerprint, mouse co-ordinates, timezone, etc
Much more likely: a manager will issue a corporate directive that everyone must begin using this password at once.
$ ./LinPass.sh luser
xTJ2B2X3
$ ./LinPass.sh luser
JzILD3qd
$ ./LinPass.sh luser
IzlXki81
$ cat LinPass.sh
#!/bin/bash
id "${1}" > /dev/null
if [[ $? -ne 0 || -z "${1}" ]]
then echo -e "Usage: $0 logname [pw]\n\treset logname's pw & force chg"
exit
fiif [[ -z "${2}" ]]
then while [[ $pw != [A-NP-Za-np-z]* ]] || # Begins with a letter
[[ $pw != *[1-9]* ]] || # Has a number
[[ $pw == *[^A-NP-Za-np-z1-9]* ]] # Has nothing else
do pw=$(openssl rand -base64 6) # Safe random source
done
else pw="${2}"fi
#echo "${pw}" | passwd --stdin "${1}"
#chage -d 0 "${1}"
echo "${pw}"
#http://brandonhutchinson.com/wiki/Linux_Password_Policy #chage -m 7 -M 90 -W 14 hutchib; #chage -M 85 -W 5 -I 5 "${1}"
Either you're expected to remember these 20-character monstrosities (which is going to be beyond the abilities of most people with 5+ accounts), or more likely you're going to be reading them from a password manager.
Being ISO-compliant is all well and good, but it's been shown many, many times that making password restrictions this extreme causes more problems than it solves.
Any internet noob searching for the most secure password might actually use it.
Half of its code points (2 ^ 64) will be characters whose glyphs are every possible combination of 8x8 bit images. That way you can make monochrome graphics simply with rows and rows of adjacent characters in the enormous sized UTF-128 font.
And imagine how many emojis there will be? There would more than one emoji for every human who has ever lived.
In short, we'll have really safe passwords using characters from UTF-128. So be patient. ;-)
EFF Diceware FTW. >128 bits of entropy there. Has uppercase, lowercase, a number, and a symbol to satisfy misguided password strength rules. Being a passphrase it's much more memorable than simple passwords. Clearly this passphrase is the best.