So yeah maybe it is implicit in the comic, but the math is backed by a specific set of assumption on how the words were selected. Or I could be wrong, I haven't verified it personally.
So yeah maybe it is implicit in the comic, but the math is backed by a specific set of assumption on how the words were selected. Or I could be wrong, I haven't verified it personally.
First character is 4 bits: c = 4
The next 7 chars are 2 bits/each: "orrect " = 14
Characters 9-20 are 1.5 bit/each: "horse batter" = 18
Charactes 21-n are 1 bit/each: "y staple" = 8
No bonus for including both upper and non-alpha chars.
No bonus for passwords of length less than 20 chars, not containing dictionary words, because the password is longer than 20 characters.
Total entropy: 4 + 14 + 18 + 8 = 44 bits of entropy.
The NIST entropy estimation is based off of characters that aren't chosen at random (I think?) and it is a heuristic.
For the approach I think Randall intended to describe they aren't really words, just glyphs chosen randomly from a set of glyphs. That these glyphs are easy to memorize and drop right into existing password interfaces is orthogonal.