Entropy of passphrases that contain pwned passwords/phrases

:thinking: Hmmm… if you are concerned about order, I would say that the alternatives are horse correct battery staple onion and onion horse correct battery staple, so there would be an additional 1 bit of entropy if that choice was made randomly.

The only viable method of estimating password entropy is to base calculations on a description of the process used to generate the password. Estimating entropy based on analysis of a single password exemplar generated from that process will never yield a valid result.

In my comment, I had made the assumption that your process was to use the XKCD example with one added passphrase word, which seems to have been a valid assumption, based on your description:

If a random password is generated by selecting 28 printable ASCII characters at random, the entropy would be estimated as184 bits, even if the generator rpoduces the 28-character string horse correct battery staple… It should be noted that the probability of this happening is vanishingly low (4×10–56).