Unpopular opinion: a 20 character passphrase beats a random 12 character password, and my login logs from 3 months of testing prove it | Cybersecurity - Opinions Matter
Unpopular opinion: a 20 character passphrase beats a random 12 character password, and my login logs from 3 months of testing prove it
Half of you will say length always wins and the other half will say entropy per character matters more, so which camp are you in and what does your actual threat model look like?