Password of three random words better than complex variation, experts say
theguardian.com
theguardian.com
So now a hacker can just claim to have forgotten my password, google for the town I grew up in or mother's maiden name or try a list of the top 100 pet names, and not have to deal with my billion-year clever password at all. So they allow you to harden the front door's security as much as you like but require you to pick one of their six easy-access window designs for the side of the house just in case you (or anyone else) are unable to get through the front door.
I can improve security by providing the wrong answer, but then I'll have to record it and won't remember it if surprised by a challenge (on the phone for example). What I always want is the option to create my own security question, because I can design one that only makes sense to me but that I can reliably answer from memory.
And voila, support person opens the door for you.
No, this won’t really protect you from a very determined attacker. Then again, neither will using a password of three random words. The endless debates about the best password policy are counterproductive. At the point it matters, you haven’t designed your security robustly enough.
It's likely way easier to memorize, not to mention type.
Though, by the same lexical token, it's worth acknowledging that words from a 170,000 dictionary will include some difficult ones that are not in the user's vocabulary.
Say we use a 30,000 dictionary of common words, and make the password four words. You know, like correct-horse-battery-staple. Wow, I remembered that.
There is a difficulty there that should be acknowledged.
For that, I'd strongly recommend simplifying your life to a dependency on fewer than 10 password-protected sites.
(Or, for Pete's sake, at least try to keep it to "a few dozen", not "hundreds".)
If you have hundreds of passwords, how many of those are critically important? I bet you could partition all those accounts into two groups: fewer than 10 that are important, and the rest. The passwords for the rest group could be heavily reused.
Like, you know that password you created on some blog site three years ago (which for some reason didn't support Google or Facebook login) just to write one comment? Who cares about it.
If you have passwords which you can easily touch type, because they are just words, then your password manager can be a 3x4 card in your wallet.
That card, rather than revealing the passwords, can just use some sort of shorthand mnemonics that only mean something to you. For instance, "correct battery horse staple" could just be noted down as a "CBHS", or some other idea.
Typable passwords are useful with any sort of manager that doesn't enter passwords for you. E.g. a hardware device with a display that just shows you the password. Such a thing will work in circumstances when you're not able to run your password manager for whatever reason.
About 15 years ago I got bit by the common mistake of reusing the same password everywhere, it was my email account and I can't believe I caught it in time before they changed the password or did anything to get my account banned. From then on, I remember just one complex password, the one for my password manager. Every site gets its own random password, as long and complex as they'll let me make it. If I get to pick a user name, I randomly generate that too, along with the answers to any security questions, which I keep in the notes section of the password manager.
By the way, for security questions specifically, I'd recommend passphrases. Often there are protocols where you need to say the security question answer to a human and they need to verify it. You're not going to have a great time spelling out a bunch of nonsense letters, and there's also more chance someone would be able to talk customer service into "oh I don't know, I just typed random keys" or something. Your password manager can likely do passphrases for you as well so it's probably no harder.