> “The best advice here is to shift your thinking from passWORDs to passPHRASES,” Snowden recommended. “Think about a common phrase that works for you. It’s too long to brute force and also make them unlikely to be in the dictionary.”
(emphasis mine)
0. http://rt.com/usa/248401-snowden-oliver-password-protection-...
https://www.youtube.com/watch?v=yzGzB-yYKcc#t=1m30s
He mentioned "margrattethatcheris110%SEXY" - I would be totally unsuprised if someone managed to crack that.
Diceware is a great choice.
While I'm asking, perhaps you can come up with a reason that doesn't boil down to "Bruce Schneirer said XKCD method was bad"?
XKCD is bad specifically because it is specifically talking about attacking a password via an internet based oracle rather than attacking a hash, but people generalized it. A search space of ten or twenty trillion is laughable when a few GPUs can make a billions of guesses per second against a vanilla hash algorithm.
Ultimately, if you want a password or passphrase that a computer can't guess, you should let a computer pick it for you, or if you're really paranoid, use diceware.