Earlier quoted context omitted.
> Worse, an attacker who sees one of your passwords has a pretty decent shot at brute forcing the rules you use, and an attacker who sees two of them has the rules and has totally cracked your scheme. If an attacker is specifically targeting me and thinking about my passwords, there's not much I can do at that point. Password security in general kind of relies on attackers scanning huge quantities of credentials and…
> If an attacker is specifically targeting me and thinking about my passwords, there's not much I can do at that point. Have really long passwords that are extremely random on a bit-by-bit basis and doesn't have a snowball's chance in hell of containing a dictionary word (which are the blindingly killer flaw in your formula). Like: 6vRmÓ£æp¥£{&XèñgäÐë¸pH©Þ|÷g¸jn§/¥ÔÎpV4fÎ or ò\f4¬Ð³ &{W+ãÄçÏ)æý½06Ýzȯ+µ>få²9Æð:WÚu >…
128 bits of security is way more than sufficient. 23 characters (uppercase, lowercase, numbers) already gives much security.
Honestly, 128 bits is already overkill. An attacker that determined is probably quite proficient at rubber hose cryptography.
The point of PW manager is to prevent compromise from spreading. Not to keep a motivated NSA out of your PC.