Earlier quoted context omitted.
A password like that would probably be guessed by a good password cracker pretty quickly. I've taken the liberty of following your procedure for an un-named domain. If anyone's got a password cracker running, I'd be interested how long it takes to break this SHA256 hash: dae640f98b6894d2f6eab5755b22918be46b0d219ea10d3ceea06ebe538a75d1. Post once you've guessed it. Just use 'pwgen -s 22'; it generates 128-bit password…
I too am interested to see how long it takes assuming the attacker knows the generator ruleset (which he will have had to work out previously from two plaintext passwords of mine). Still, I don't think it's that easy to figure out the ruleset of a good password generator if you make it obscure enough. For example: Amazon: NovemberAlphaies12# Facebook: KiloFoxtrototto16& What's the ruleset? Answer: Phoenic alphabet of…
I dunno, seems like way more work to come up with, maintain, and actually use the generator. Seems easier to just click a bunch in my vault to generate and copy, although I guess you're protected from vault-theft?
Given your example, I had already figured out all the way up to ies/otto are probably foreign numbers (more specifically, otto looks like 8 and 16 looks like double of 8) before even seeing that you just gave the answer away.