I will note that the XKCD password scheme being proposed there is, in fact, completely insecure. A single modern consumer GPU can crack "four random English words" in a day. You can argue that it's the user's choice to be allowed to use insecure passwords, but arguing that that scheme is actually secure is just wrong.
zuzululu•29m ago
amelius•6m ago
VorpalWay•3m ago