DvAvRxiBAZaI1A3R
Horse.. in a box riding a fish!
Which one would you prefer to memorize and type in?For comparison, the first password you provided (16 random alphanumeric characters) has 95 bits of entropy.
[1] http://books.google.com/ngrams/graph?content=horse+in+a+box%...
echo $( shuf -n 4 /usr/local/share/4000-common-words )4000^4 gives 256000000000000 giving 3.3 bits of entropy per decimal digit it comes to 50 bits of entropy. Not too shabby but not that secure either. Your PCs rng may play you dirty tricks.
And of course there are all kind of legacy systems with password limitations to 32 or 16 character, but above 8 etc etc which would further reduce the pool.
Of course you could try your own password deriving mechanism. Take the first 16 characters of bcrypt(username,site domain) it will produce awesome passwords for any site that you will have easy time producing when needed. Until the hackers begin to suspect what you use if it becomes widespread.
(Disclaimer - not a cryptographer or security expert or particularly competent in anything)
Hey, that's the very definition of security through obscurity ;)
Here's a thought experiment I use when estimating security of similar password schemes: imagine you asked someone to come up with 1000 different mechanisms of generating passwords based on username and domain. Is your scheme is likely to be among them? If yes, this means it provides less than 10 bits of security.
Maybe that's no longer secure enough; I don't know how fast password crackers are now. So use "shuf -n 5" instead.
Please don't discourage good practices. Four random words is a lot better than "password123", though it would still take 1.5 day to crack it if it were stored as an MD5 hash. Six words would take 65 years at 1ghash/sec, which is pretty damn good, and better than a 12-char random password. 5 words would take 16 years, which seems like a pretty good compromise.
EDIT: Although, I don't like straight-up Shannon entropy as a measure of password strength.
Any password derivation scheme works brilliantly until you are the only one using it. The moment it becomes widespread and people begin to target it - it goes anywhere from significantly weaker to trivial to crack.
On a related note, has anyone analyzed the entropy of markov chain generated passphrases?
http://apocryph.org/archives/556
and
http://apocryph.org/archives/693
Summary: Highly entropic Markov-generated phrases are long and hard to remember.