We're already at the point where
any phrase from any book ever written is probably insufficiently secure. (Mixing phrases from multiple books might work.)
We've got a few parameters to work from here:
- By a Google Books estimate from some years back, there were roughly 140 million books ever published. That's been going up by ~1--5 million a year for the past decade or so (only about 300k are "traditionally" published). See Bowker.
- If we limit ourselves to a reasonable canon -- the 100, or 1,000, or 10,000 most-frequently-read books, that number goes down a lot. (Twenty years ago when I had this conversation at work with a user, I said "a phrase from Alice in Wonderland isn't obscure enough. They'd chosen lines from "Jabberwocky", and no I'd not run a cracker.)
- A typical book runs about 250 pages, at about 500 words per page, and about 10 words per sentence. That's about 125,000 words, or 12,500 sentences, per book. Even assuming no sentence ever repeats (they do), that's "only" about 1.7 billion sentences in all published books. For the top 10k, it's only 125 million, the top thousand and 100 are 12.5 and 1.3 million respectively.
Computationally and cryptographically, those are small keyspaces.
Oh: and many of those books are scanned and OCRed. ZLibrary (from which LibGen and other sources pull) has over 8 million books (http://zlibraryexau2g3p.onion/) --- approaching that of a substantial university library collection (The University of California library system has 40.8 million print volumes across 10 campuses and 100 libraries, with 4.3 million digitised in HathiTrust: https://libraries.universityofcalifornia.edu/about/facts-and...).
Randomly-gathered words (EFF Diceware or xcdpass, see https://www.eff.org/dice or https://pypi.org/project/xkcdpass/) are robust --- we don't just combine words at random typically. And as mentioned, joining phrases from different books should be reasonably memorable (combinatorics work in the defender's favour).