The most useful thing we can do as web developers:
- support very long passwords, so that users can use pass-phrases if they like.
- use bcrypt or the like for storage
- do not create easily cracked side channels, like a fixed set of "security questions" for forgotten passwords