However, I wonder how safe it is to take an "easy" password like /.,/.,/., and then add a bunch of exclamation points to the end, so that it's both long and not part of a dictionary.
I'm sure password crackers are advanced enough to first try taking common passwords and then adding human modifications to make them more secure.
But something like MyDogRules###########! seems like it could be very secure, actually.
Mr. Asdf sir
My Fav0riT Pas%werd
is actually pretty solid compared to
df22@$Fasdf
because the latter is more crackable
It also doesn't require any special characters and its quite easy to remember.
The problem is, after I've committed a long passphrase into muscle memory, it probably takes me less time to type a 40-character phrase than count 40 individual keypresses of a button hoping I don't miscount.
* Assuming nobody is stupid enough to make a depth-first password cracking program. "I'm down to a billion 'a's now. I should be ready to try a 'b' any minute now!"
[0]https://arstechnica.com/information-technology/2013/05/how-c... (OK, the passwords were hashed only with MD5)