Just noting that "Cheswick" is the dude that literally (co-)wrote the book on firewalls (1e in 1994):
* https://en.wikipedia.org/wiki/Firewalls_and_Internet_Securit...
Just noting that "Cheswick" is the dude that literally (co-)wrote the book on firewalls (1e in 1994):
* https://en.wikipedia.org/wiki/Firewalls_and_Internet_Securit...
But now that you mention him, the man was working at Bell labs during the time when Ken wrote his famous essay "reflections on trusting trust". If he shared just a small part of his colleague's spirit, it would be irresistible to him to log all passwords that thousands of people may decide to use. Mainly as a conversation starter, not to do anything bad with these passwords. Maybe he's gathering cool stories in case of a hypothetical Turing award in the future?
GP was arguing that OP is trustworthy because he has a reputation to maintain.
I, the GP, is arguing nothing of the sort.
That being said, there's no need to use 3rd party password generators, if you can make your own.
Really?
1. It’s from a known-reliable source
2. Even if the password is stored, logged, broadcast around the world for billions to see, so what?
A. Source has no way to know if the user used the password anywhere or saved it
B. Source doesn’t know who the user is
C. Source doesn’t know in which website or resource the password was used.
So… I stand by my paranoia claim. I wouldn’t go so far as to call you foolish like you did me, but I’d say such a world view will not be a net gain for you over your lifetime. You’ll have difficulty delegating work. You’ll have major trust issues. Maybe you already do. But as they say, “you do you.”
But being able to inspect (theoretically even audit) the source, building (if necessary) and running it locally in some container/sandbox without network connection would be minimum reqirements for me.