There is certainly some truth to this post, especially right at this moment in time. But it's the most exuberant example I've yet seen in a new category of bad password advice, to ignore everything but length.
A truly random eight character password containing upper and lowercase letters and digits is a keyspace of size 2x10^14. A four word passphrase containing random words selected from a 5000 word dictionary is a keyspace of size 6x10^14. They are comparable.
Right now, since almost everyone uses short passwords, length gives you amazing protection, because attacks are geared to find the common short password. But to the extent that the tech elite convinces the world to move to longer passphrases, that will quickly stop being true. It's no harder to program a brute force attack to try phrases of very common words, or very long, very low entropy phrases of other sorts (to be or not to be), than it is to try variations of dictionary words.
To the extent that we are giving people advice on security, it should be advice that is robust against the possibility of its own success.
A truly random eight character password containing upper and lowercase letters and digits is a keyspace of size 2x10^14. A four word passphrase containing random words selected from a 5000 word dictionary is a keyspace of size 6x10^14. They are comparable.
Right now, since almost everyone uses short passwords, length gives you amazing protection, because attacks are geared to find the common short password. But to the extent that the tech elite convinces the world to move to longer passphrases, that will quickly stop being true. It's no harder to program a brute force attack to try phrases of very common words, or very long, very low entropy phrases of other sorts (to be or not to be), than it is to try variations of dictionary words.
To the extent that we are giving people advice on security, it should be advice that is robust against the possibility of its own success.