What's wrong with long password with all lowercase characters which are not picked randomly? Apart from someone looking at you typing, why would "fuwaiunviohugihyeurpqwjiosnxjcewiorhewuioahfdsfeaw" be worse than "i like unicorns in the morning and hedgehogs in the evening"?
There's nothing really wrong with that as long as it's not predictable in some way. For example, if you knew that all my passwords were song lyrics in lowercase then you could attack my passwords using list of all the world's song lyrics (which would be much smaller than all random lowercase strings of length X).
If you come up with something you can remember that's long and unlikely someone else can guess the search space for then you'll be ok.
In a sense. But it's a principle of cryptography that you assume the attacker knows all your schemes / algorithms, and only the random bits are secret.
If those become common enough, then you have reduced your symbols from 50 (your first example) to 11 (your second) where five ("in the and in the") are typical joining words. We can imagine password crackers can just combine the words in the dictionary just like they currently combine letters and give a higher priority to looking for combinations of conjunctions. The random letters make these approaches a lot more difficult.
It depends what you mean by "random" in this case. Things that would not be random include all-lowercase passwords drawn from personal things such as your name, kid's names, etc - things that can be guessed/found through research.
The long passphrase sentence you posted that happens to be all lower-case letters is seemingly random though.
Comments
What's wrong with long password with all lowercase characters which are not picked randomly? Apart from someone looking at you typing, why would "fuwaiunviohugihyeurpqwjiosnxjcewiorhewuioahfdsfeaw" be worse than "i like unicorns in the morning and hedgehogs in the evening"?
There's nothing really wrong with that as long as it's not predictable in some way. For example, if you knew that all my passwords were song lyrics in lowercase then you could attack my passwords using list of all the world's song lyrics (which would be much smaller than all random lowercase strings of length X).
If you come up with something you can remember that's long and unlikely someone else can guess the search space for then you'll be ok.
If I knew your passwords were all song lyrics, that's already a failure of security.
In a sense. But it's a principle of cryptography that you assume the attacker knows all your schemes / algorithms, and only the random bits are secret.
Your scheme can be a few more random bits, selecting from a finite number of "schemes".
Yes.
If those become common enough, then you have reduced your symbols from 50 (your first example) to 11 (your second) where five ("in the and in the") are typical joining words. We can imagine password crackers can just combine the words in the dictionary just like they currently combine letters and give a higher priority to looking for combinations of conjunctions. The random letters make these approaches a lot more difficult.
It depends what you mean by "random" in this case. Things that would not be random include all-lowercase passwords drawn from personal things such as your name, kid's names, etc - things that can be guessed/found through research.
The long passphrase sentence you posted that happens to be all lower-case letters is seemingly random though.