Reuse is the biggest risk
The most common way accounts fall is not guessing but taking a list leaked from one service and trying it on others. However complex a password is, reusing it across sites means one breach opens all of them. Making them different comes before making them complicated.
Length over complexity
Requiring capitals and symbols is an older standard; length matters far more in practice. A long passphrase built from several memorable words is both safer and easier to remember than something short and convoluted. Using a well-known quotation verbatim is the case to avoid.
Using a manager
If everything is different you cannot memorise it, so it has to be stored somewhere. Dedicated managers are built for this, and you only memorise one master password. Whatever you use, a breach of the store exposes everything, so the master password must be one used nowhere else.
- Dedicated manager: designed for the purpose
- Browser storage: convenient but rests entirely on device security
- Notes apps: risky unless encrypted
- Paper: safe from online leaks, weak against loss
Two-factor is the practical defence
It is realistic to assume a password can leak at any time. With two-factor enabled, knowing the password is not enough to sign in. An authenticator application or a hardware key is safer than codes by text message, and whichever you use, store the recovery codes separately so losing a device does not lock you out.
Work down by importance
Trying to fix every account at once means never starting. Begin with accounts that act as a recovery route for others. If your email is breached, everything else can be reset through it, so that comes first, followed by anything holding financial or payment details, then the rest.
🌍 Search the web for this
Each button runs this keyword on that search engine