We present a large-scale study that investigates password
strength, user behavior, and user sentiment across four
password-composition policies. We characterize the predictability
of passwords by calculating their entropy,
and find that a number of commonly held beliefs about password
composition and strength are inaccurate.
We correlate our results with user behavior and sentiment to produce several
recommendations for password-composition policies that resulted
in strong passwords without unduly burdening users.