1. 5

The PDF of the full article is available from the ACM digital libary here

  1.  

  2. 3

    Modern browsers offer to remember passwords, why not offer to generate them as well? Assuming most users let the browser remember their passwords, it makes sense and would actually slightly reduce the hassle of signing up for an account. Of course it wouldn’t be perfect, but at least people would stop using “password1.” and the like.

    1. 2

      Safari actually does this. I believe it generates 3 sets of 4 alphanumeric characters so you get 36^12 bits of entropy.