An Observation About Passphrases: Syntax vs Entropy
This addresses password security for users and system designers, but it is incremental as it focuses on a specific aspect without broader comparisons.
The paper tackles the problem of whether syntactically correct passphrases enhance security compared to random word collections, finding no significant impact on security based on syntax alone.
On the premise that we are using passwords composed of multiple English words, we argue that using syntactically correct passphrases has no significant impact on the security in comparison to randomly arranged collections of words. We only analyze the contribution of the syntax itself. A comparison to the other kinds of passwords is out of the scope.