^ But what kind of person would ever type their password into an unknown website to see how strong it is? Surely not one in ten million people would ever do it.
As a side note, my password is entirely secure becaue it uses fractional ASCII, so I can use letters halfway between 'A' and 'B' or 3/4ths 'D' mixed with 'C', or even irrational numbers like sqrt(2)*'F' + 'G' Sadly, most password programs don't yet recognize anything but standard ASCII, so often I'm forced to resort to EBCDIC or Baudot. For example, I manually translate ASCII 'GTurner' to EBCDIC 'GTurner', then type it in the result (which ironically is still 'GTurner' for some mathematical reason that eludes me), confident that no machine can crack it within the lifetime of the universe, as having a password that matches the username is the last thing an intelligent program would ever try.