A different approach would be for him to write an open-source program that generates the passwords on your local machine. Of course, if it is distributed as an executable, you don't know if the executable is the same as the source, but you are already trusting him now on the program on his web site.

Given that most users of this would be Windows folks, one could possibly write a really creative batch program to do this, thus eliminating the worry about the difference in executable. It would be mostrously ugly, but a nice hack.

