Meccha Entropippi めっちゃエントロピッピー

Alex Stevovich's portrait
By Alex Stevovich

So. This month my favorite kawaii J-pop female group, のんふぃく! (Non-Fiction aka. NONFIK), released a new music video. This isn't actually a new song. NONFIK debuted it live at their fourth-anniversary concert in May 2025, and it has since become a staple of their live shows and short-form videos, but this is the first time it's had a full music video. The song/video is a high-energy, super-kawaii experience, and I think it's a great one. There was some minor controversy around the AI-generated castle footage in the opening frames, but this feels fairly inconsequential to me, or at least part of a much larger industry-wide discussion that HEROINES, the agency umbrella that includes NONFIK, isn't really positioned as a global production leader to resolve.

  • 【MV】うれぴっぴ!/ のんふぃく!【ノンフィク】

One of the song's central refrains is めちゃうれぴー。めちゃちゃちゃうれぴー。 (meccha urepī, meccha-cha-cha urepī), roughly “SO HAPPY! SO-SO-SO HAPPY!” Meccha is essentially “really” or “super,” while urepī is a deliberately cute way of saying you're happy. The song takes this silliness even further with urepippī and tanopippī, basically escalating happiness and fun into increasingly ridiculous cute noises.

The song describes a strategy for turning a bad day into a good one simply by becoming extremely happy through dancing. Bad day / stressed / angry → do the silly Urepī dance → smile → MECCHA HAPPY UREPIPPI!! This almost becomes a philosophy of weaponized happiness. When the world is making you miserable, respond with HAPPINESS HAPPINESS MORE HAPPINESS!!!

I was inspired by this strategy, and when I heard it I wondered: what if I applied the same philosophy to cybersecurity? When hostile actors are attempting to crack, hack, or access my accounts, perhaps I can respond to adversity in much the same way: but instead of happiness I will use VERY SUPER ENTROPY!

Could I generate entropy as easily and enthusiastically as the members of NONFIK generate happiness, and use it to overwhelm the threats and assailers arrayed against me? Their song proposes HAPPINESS HAPPINESS MORE HAPPINESS!!!

My "song" proposes:

ENTROPY ENTROPY MORE ENTROPY!!!

🩷🩵💛💚❤️💜💙🤍🧡 oooooooooooOOOOOOOOOOOOOOOOOOOO YEAH!

Disclaimer

This article is a theoretical musing and exploration into fun spaces of cryptography, as a thought experiment. Nothing I express here is security advice or should be practically implemented as a real-world solution. The point of this article is conceptual discussion.

The Thief

  • Photo of my monitor in my office

Consider a simple scenario. You are a thief. You have infiltrated my office, and on my monitor is a sticky note that says: My bank account password: tifalockhartforever24. You now have a very obvious course of action. You try the password. Either it works, or it doesn't. If it doesn't, you've exhausted the value of that particular piece of information within a few minutes.

Next imagine the same scenario, except there are a billion sticky notes on my monitor, each claiming that my bank account has a different password. One of them might be correct. None of them might be correct. You can investigate them, but the problem has fundamentally changed. What was previously a single highly actionable piece of information has become an enormous search problem.

Now imagine there is also a large note that says: My password is made from some combination or subset of the information on these sticky notes. The problem becomes considerably larger. Perhaps some notes should be placed before others. Perhaps groups of two, three, four, or more should be combined. Perhaps only substrings matter. Perhaps those substrings should be reordered, repeated, encoded, hashed, transformed, combined with the results of other transformations, or fed recursively into still further transformations.

Because no limit has been placed on how the material can be assembled or transformed, there is now an infinite space of possible derivations.

The billion sticky notes therefore do something more useful than merely create a very large collection of possible passwords. They make it increasingly difficult to determine what is signal and what is noise.

There is also one final possibility: None of it was real.

This is the basic security proposition behind Meccha Entropippi. If one piece of information about you might matter, what happens when there are billions? Meccha Entropippi explores the idea of publishing a lifetime of plausible noise around yourself, making it increasingly difficult and expensive to determine what means anything at all.

Passwords in Art

  • Becky Brown, My Passwords, 2020. Acrylic, house paint, pencil and ink on paper. 77 x 55.5 inches

Becky Brown's My Passwords (2020) is a brilliant piece that ties unexpectedly into the central thesis of this article. At 77 × 55.5 inches, Brown takes the familiar appearance of an ordinary handwritten password list and blows it up to absurd, monumental proportions. Most critically, she simply puts the passwords on display.

In the terminology of this article, I can't help seeing My Passwords as an exceptionally elaborate and artful Meccha Entropippi, and she did it years before I coined the term.

For most people, cybersecurity eventually becomes passwords, scraps of paper, recovery codes, forgotten credentials, increasingly elaborate rules, and whatever personal systems we devise to survive an increasingly hostile digital environment. To me My Passwords elegantly captures something absurd and deeply relatable about modern security: behind all of the sophisticated cybersecurity, eventually there is just a person trying to remember their passwords.

Entropy

Entropy is a measure of uncertainty or unpredictability. In cryptography, it is commonly used to describe how difficult something such as a randomly generated password or key would be to guess. Throughout this article I also use entropy somewhat playfully as a noun meaning a quantity of random-looking data. For example, I might call this “a lot of entropy”:

90fd7c5ed4d060c121083b4ac9d99a32f7583285837bd78f02352079bd4306c5d6a9a0e91b09aae1e7a97b015ea799ad72464cd5a4a9e428d6846c6f3ab4caaa7d278031227da8ad5bb1d84d943e5eb5ae3adb7e44879dd29610b11aa480563c7f34963e7bfe780b50a5d5105c65e42e1afef58195380b609f1a028243b2fe15c57361ab13426cbb563a812b824ac6a5302a542892ed6a5c32900450867e907c

Technically, the string itself doesn't tell us how much entropy went into it. That depends on how it was generated.

Glossary

  • Entropy: A measure of randomness or unpredictability. In security, higher entropy generally means something is harder to guess.
  • SaaS: Software as a Service. Software that is provided over the internet rather than simply installed and run locally. Anything you make an account for in a website is usually some type of SaaS.
  • J-pop: Japanese pop music, a broad category of popular music originating in Japan.
  • Cryptography: The methods used to protect information by encoding, encrypting, signing, or otherwise securing it.
  • Hex: Short for hexadecimal, a 16-symbol numbering system that uses 0–9 and A–F. Commonly used in computing to represent binary data more compact.
  • Kawaii: Japanese for “cute,” especially something with an intentionally adorable, charming, or playful quality.
  • Obfuscation: Deliberately making information or code harder to understand while still allowing it to function.
  • Group Member Color: A color assigned to an individual member of an idol or pop group as part of the group's visual identity. It is used in costumes, merchandise, graphics, fan lights, emojis, and other contexts to identify or represent that member.
  • SHA: Short for Secure Hash Algorithm, a family of cryptographic functions that turn data of any size into a fixed-length value called a hash.
  • Noise (Math Sense): Random or irregular variation in values, often generated mathematically to create complex variation or texture.
  • String: Programming term for a sequence of text characters, such as a letter, word, sentence, or any other piece of text.
  • Hai, sē no!: A Japanese phrase (はい、せーの!) roughly meaning “Okay, ready, go!” used to cue people to begin or do something together.

Hai, sē no!

Meccha Entropippi is a thought experiment understood as the strategies and constraints to think about the idea. (One last reminder for posterity: none of this is a suggestion to actually do it. See the disclaimer above. Onward.)

The Naked Motel Test

My personal security strategy has one unusual criterion. I should be able to wake up naked in a motel in a foreign country on the other side of the planet, with no possessions and no phone, and still regain access to my digital life with relative ease.

I can't depend on anything I physically possess to tell me what my master password is, and losing my second factor cannot permanently lock me out.

This sounds like an intentionally ridiculous scenario, but I think the underlying concern is practical—perhaps increasingly so in what often feels like a destabilizing world.

This exposes a blind spot in modern security advice. Physical security keys, trusted devices, and offline recovery codes can provide excellent security, but they also create physical dependencies. If my security ultimately requires this particular object, I need a plan for if and when that object is gone.

A corporation can build infrastructure around its security model: redundant facilities, administrators, geographically separated backups. An individual is one person, and we sleep, travel, get sick, lose things, and get older. A theoretically excellent security architecture that requires permanent and flawless management may be a poor personal one.

Modern security still tends to leave an individual with one extremely important secret somewhere. A truly random secret with real security margin (say, 64 hex characters, 256 bits) is fantastic for a computer and miserable for a brain to remember. Password managers help, but the recursion has to stop somewhere: I need a password for my password manager.

The bluff of Meccha Entropippi is the massive convenience and peace of mind that would come from daring to hide your password in plain sight, publicly.

Public Publishing

I could "entropically poison" my own computer with random data, but that localizes the idea: it tells an attacker exactly where the interesting corpus lives. I find public Meccha Entropippi more interesting. A public corpus has a different property: I cannot lose it. It's also unkillable by the exact disaster that might have caused the Naked Motel Test: home and paid hosting could go dark as collateral to an event, but a free public post on a SaaS just sits there, waiting...

64-Character Hex

For the noise itself, I prefer blocks of 64 hexadecimal characters. It happens to be exactly how SHA-256 hashes are usually displayed, making it one of the most ordinary-looking forms of machine noise on the internet, showing up everywhere from file checksums to crypto wallets.

Compare that to passwords like bluedragon1995! or tifalockhartforever24. Those look like passwords because humans put personality into passwords and the care I might put into some over others starts leaking information. A random hex block is mundane.

💚やりゃ できんじゃん

  • 【MV】うれぴっぴ!/ のんふぃく!【ノンフィク】
  • https://www.youtube.com/watch?v=c-q7CKj2cRU 2 Minutes 8 Seconds

At the pinnacle, mic-drop moment of the song, Marin—the green member—declares 💚やりゃ できんじゃん (yarya dekin jan), which roughly means:

"See? You CAN do it!"

And I'm here to tell you that you ALSO can do Meccha Entropippi.

Or can you...

I speculate that free SaaS hosting might actually be the best place for this. That gives us plenty of possible hosts: social media, source control, forums, email, distribution platforms and whatever else will accept arbitrary user-generated data. The possibilities are nearly endless and can get increasingly creative, but to name a few basic ones:

  • You can pad the remaining allotted characters of social media, forum and comment posts with random entropy.
  • You can DM people and yourself entropy. Friends will love it.
  • You could speak with AI models in shared public conversations and have them talk about your entropy.
  • You can distribute your entropy as products for free.
  • You can source-control entropy and even have versions of entropy.
  • You can publish games that do nothing but show entropy.
  • You can set public profile data to entropy on any service.
  • Even non-random information can become entropy noise. Any file, text, statement, or image can be hashed into a SHA-256 value and potentially used as a credential or component of one. In this sense, an endless social media feed of lunch and cat photos can contribute just as readily to Meccha Entropippi as a page of random hex.
  • This can expand further into concepts like or adjacent to steganography, which is encoding data secretly in images. It can be applied to almost anything.
  • 72410cedb74a02c91ee28f9aba14369fc944807fa92e541b236bacb70f87569a46a22cf578ec338d765a893cc0a3fb2d12950569f65e81f2d793bb33f0d9bac0d70158333beab4629706e863419d8bca84432857560b1b870198277b0b18051953ba8252c46e773f04650a463440e1a30f3610d47b6f2d181e2b37f2f3d19fccbb694b81948856b4a40adc4575f3d338c4cacdf9dd0b8a92a126289f7290d8f7613018fa25c3e436b38bfd42d39d2419a03424fefa365264cc3718fb1893f0b937fe6180fb26ff9a57037de40877b8817aa150d957fcd62355258d93eb6e725f8ff3390c8f223c5c6d8029b34571634b243002e7d67b0da28149cb1fdf08ec0c63d50e19624fd4d5131426284838b212ed289c3a627d3cf7d497768524d19b5c16348adb8ec29a705a28beb879cf37f4cf1766c58cdcbe9e4d99d24d816e5ed0

However, I would not be quite as zealous as Marin on this particular subject. These companies will happily tolerate endless quantities of human language but may become considerably less enthusiastic when that language turns into endless quantities of noise. How much they tolerate will naturally vary by platform.

There are probably enough legitimate avenues that, over a lifetime, you could accumulate an unreasonable amount of publicly associated entropy without any single location containing very much of it at all.

There's also a very bright side: The SaaS companies mutually benefit from this by having all your personal entropy to sell to brokers, and also they can use your personal entropy to train their AIs on.

So really, it's a win-win for everyone. The platforms get to sell your entropy. The AI gets better by training off your entropy. You get your own personal entropy. And we can all be MECCHA-CHA-CHA VERY SUPER HAPPY about it.

© 2026 Alex Stevovich

About the Author