At first, I figured this could be used as a case against Randall Munroe's password generation algorithm [1]. But it looks like the problem is with Apple's implementation, not with the method. The abstract claims that "the process of selecting words from that word list is not random at all". I wondered how not-random the selection was. The paper says: "words from this Top 10 list are ten times more likely to be selected as a default password". The word frequency distribution graph [2] is pretty damning.<p>[1]: <a href="http://xkcd.com/936/" rel="nofollow">http://xkcd.com/936/</a>
[2]: <a href="http://imgur.com/nAKkPe3" rel="nofollow">http://imgur.com/nAKkPe3</a>