Their passwords do have 60 bits of real entropy, but the estimates in the article aren't based on how long it would take to brute-force a 60-bit password - according to the paper, that would only take 11.3 years on a single (2011-era) GPU, rather less than the 5 million they told the Washington Post. At a guess, they're counting the entire 79-bit poem pool they're culling the actual valid passwords from, on the assumption an attacker will have to test all of them. (The algorithm maps those 60 bits onto one-million-poem wide slices of the pool, and returns only the one that looks most like valid English.)
You can also memorize a sentence or a paragraph from a book that you love and own (which also can be used if you ever forget, or need to share the password with anyone)).
Comments
Their passwords do have 60 bits of real entropy, but the estimates in the article aren't based on how long it would take to brute-force a 60-bit password - according to the paper, that would only take 11.3 years on a single (2011-era) GPU, rather less than the 5 million they told the Washington Post. At a guess, they're counting the entire 79-bit poem pool they're culling the actual valid passwords from, on the assumption an attacker will have to test all of them. (The algorithm maps those 60 bits onto one-million-poem wide slices of the pool, and returns only the one that looks most like valid English.)
Hence my suggestion to memorize two such passwords.
You can also memorize a sentence or a paragraph from a book that you love and own (which also can be used if you ever forget, or need to share the password with anyone)).
Better pick an obscure book, I've read about cracking programs with books in their dictionaries.