Derek Thompson

When Derek talks about password strength, he starts with the numbers. His articles focus on what strength meters are actually measuring underneath the interface and why two different tools can score the same password differently. He likes pulling apart the math behind entropy estimates and showing where those calculations hold up or fall apart.

He spends a lot of time on edge cases that strength meters handle poorly. Passphrases made of real words often confuse tools built for character-based passwords. Generated strings with recognizable patterns can score high on paper but fail in practice. Derek walks through these scenarios with concrete examples so readers can spot the gaps in their own tools.

He keeps his writing strictly informational. Derek explains what metrics mean and how they're calculated, but he avoids telling readers that any particular password is safe or sufficient for their specific accounts. He figures that decision depends on what's being protected and recommends people weigh their own threat level.

Articles by Derek Thompson

How to Create Pronounceable Random Passwords for Non-technical Internet Users
Say your password out loud right now. If you can't speak it without spelling each letter, your brain will drop it within a week. That's not a guess.
Why Excluding Special Characters Weakens Random Password Security
The Misconception: "I'll Just Make It Longer Instead" You're sitting in front of a password generator. You see the checkbox labeled "Include special characters."

Other writers on Strong Password Generator