1Password should by default just always capitalize one word, and add “1” at the end of the memorable password. Since the words are separated by “-“ or “.”, you already hit the “at least one symbol” rule.
- Password must be at least 12 characters long.
- And the password must also contain either of the following:
- A phrase containing at least four unique words of three characters or longer
- or password contains at least 3 of the following qualities:
- uppercase letters
- lowercase letters
- numbers
- punctuation characters
- or more than 12 characters
I went with the phrase option.AgileBits obviously has done a lot more profiling, but it would be nice if they developed a universal password formula that was still memorable. So with words, “-“ separator (or maybe “.” separator?), maximum length 18, one whole word capitalized, random single digit at the end or beginning.
That way you keep maximum entropy, keep it readable, whilst fitting within the rules of “all” sites.
Although within 5-10 years I see passkeys having largely taken over, especially because mom and pop won’t be able to forget those, and they won’t be able to forget their fingerprint or face either.