What are the risks of a password attack?
* Someone can watch you type in the password
* Someone can receive/sniff/keylog you typing in the password
* Someone can find the password database and crack it
* You might tell the wrong person the password
* If you wrote the password down, someone might find it
* More i'm not thinking of (probably)
There is some kind of attack that will work to get your password, I guarantee it. So stop obsessing over it. Just make one difficult password, keep it for a long time (as suggested in the article) and make use of a second authentication factor.Use a keyfob from PayPal or Verisign combined with OpenID ($5-$40; there are other cheap keyfobs out there too). Soft keyfobs are free and (while not impenetrable) present a new mandatory additional attack vector that increases complexity. It's less secure, but you can also use an SMS-based system for another free and cross-platform alternative.