I found the first part of the post a little bit cryptic (no pun intended). Since the second part is not just aimed at an audience with technical security knowledge, maybe at least including Shannon’s maxim and a link to outfo-hazard (ok, that one is not technical) would help. Though after googling it, I still don’t understand the part about Shannon’s maxim, e.g.,
Generating a password with a high amount of “entropy” is just a way of ensuring that password crackers are very unlikely to break them without violating Shannon’s maxim.
If Shannon’s maxim is: “The enemy knows the system”, violating means that they do not know it? How does not knowing the system help crackers crack high-entropy passwords? Or is “violating Shannon’s maxim” to say that the attacker knows the secrete key? In that case, wouldn’t it be better to say “violating Kerckhoff’s principle”? (I prefer Kerckhoff’s principle anyway, Shannon’s maxim seems IMO just a more cryptic (sorry again) restatement of it.)
Otherwise, nice post.
One of the entrances to Theaterberg is closed, but you can take the other one or just sneak your way past the barricades.