>passwords
isn’t there some law about trading stolen passwords?
I’m a fan of easy to type passphrases designed to spark a riot if ever read in open court since this seems to be a common pivot from the “look the other way when the user types” model I followed when I worked a help desk. We were told when I moved on to Hci research it’s unethical to collect the passwords, there’s a whole cottage industry of academics analyzing leaked data sets since they aren’t allowed to… just ask.
(I’m not Irb certified and not a professor, so I get to do whatever I want.)