Earlier quoted context omitted.
A line from a song is far weaker entropy-wise due to grammar. I wonder by how much. Common songs/writings would be vulnerable to a dictionary type attack. As for the hundreds of passwords in your list, I'm convinced a password manager with a master password/3rd party auth/dongle is the way to go. Otherwise it's impossible to have unique passwords for all sites, rotate them, and remember them. Of course the risk is of…
> A line from a song is far weaker entropy-wise due to grammar. Interesting observation, the usual objection is due to the reduced Kolmogorov complexity which is difficult to quantify. Let's look at a modified diceware scheme of the form: Article adjective noun adverb verb adjective noun A (non-random) example might be: The young boy really likes video games. I'm not going to go through the diceware word list and cla…
If we go back to the original 'song verse' idea, the space of all valid/written phrases is much smaller than the space of all possible word combinations. It's vulnerable to dictionary attacks based on commonly chosen phrases and frequency of phrase use in language/culture.
Wikipedia only has 2.4 billion words, out of an estimated billion English words [1]. Perhaps we could add project Gutenberg with it's 50,000 works, and all the song lyrics we could find on the internet. We may hit 5 billion words. Let's estimate we also get 5 billion 6-word phrases out of that set. We've lost a ton of entropy.
Ultimately, we suck at passwords. Machine capability will exceed what we can reliably, efficiently memorize.
[1] http://www.languagemonitor.com/number-of-words/number-of-wor...