Originally Posted by
colonius
Everybody with a short password (less than eight characters) should be aware that a brute force attack will uncover it in a few hours (total time for yours and any other similar weak password in the system). Since it is a brute force attack, even a password like "gHj87Q" offers no protection. Also, dictionary attacks can be quite successful - how many of you have a common English word or name as a password? Those take minutes.
I’ve never used words or phrases, just a series of random letters and numbers for website passwords. This may sound like a pain to manage, but there are a number of utilities that can organize passwords securely. I’ve been using
PasswordsPlus for several years now, but there are some free ones out there as well, such as a plugin for Firefox I believe.