Thanks, that is interesting and kind of matches my reasoning.
I have a feeling the debate is a bit colored by leftover paranoia from the times when several users shared one computer and the password database was easy to get hold of.
Unless the attacker somehow manages to grab your password database (and not your content, which would be an interesting setup in itself) he won't be able to brute force you. He will only be able to lucky-guess you. And you don't need 24 random characters to block a lucky guess scheme. :)
I have a feeling the debate is a bit colored by leftover paranoia from the times when several users shared one computer and the password database was easy to get hold of.
Unless the attacker somehow manages to grab your password database (and not your content, which would be an interesting setup in itself) he won't be able to brute force you. He will only be able to lucky-guess you. And you don't need 24 random characters to block a lucky guess scheme. :)