Derek Thompson
When Derek talks about password strength, he starts with the numbers. His articles focus on what strength meters are actually measuring underneath the interface and why two different tools can score the same password differently. He likes pulling apart the math behind entropy estimates and showing where those calculations hold up or fall apart.
He spends a lot of time on edge cases that strength meters handle poorly. Passphrases made of real words often confuse tools built for character-based passwords. Generated strings with recognizable patterns can score high on paper but fail in practice. Derek walks through these scenarios with concrete examples so readers can spot the gaps in their own tools.
He keeps his writing strictly informational. Derek explains what metrics mean and how they're calculated, but he avoids telling readers that any particular password is safe or sufficient for their specific accounts. He figures that decision depends on what's being protected and recommends people weigh their own threat level.