I read an provocative estimate a year or so ago that each extra
character of a password adds only on average 1.5 bits of entropy to it.
~ Considering how most passwords are formed from dictionary words, albeit
slightly modified or appended, it sounds about right.

And that's ignoring the passwords that are some variation of 1234,
"password", or are to be found underneath the keyboard[1], etc.

- -Andy

[1] The case in Zaavi shop in Oxford Street, London I was amused to
discover recently.  And the Three shop in Kettering actually had their
login credentials laminated and pinned to the wall for all to read --
how many bits of entropy is that despite the huge "password space" that
could exist?

