Once you've chosen to use unique passwords everywhere (and you're insane not to these days), you're effectively committing to some form of password storage, so whether or not "hard passwords" are pointless, they're just easier. I just use 1Password to generate strong 16char passwords because it's easier/quicker than "thinking up something random enough and recording it somewhere suitable".
Sure there's the "all eggs in one basket" problem with my 1Password database, but it's got a strong (~25char) pass phrase, and even then there's a class of passwords I store only on my head. My 3 banking passwords, my pgp key pass phrase, my root passwords, and my DNS registrar passwords.
One thing I think people often overlook is that your DNS registrar access credentials trump your email's two factor auth - if I can change your MX records, nothing you've done to secure your email account matters - I'll just get everyone to send your password reset requests to a mail server under my control…
Comments
Once you've chosen to use unique passwords everywhere (and you're insane not to these days), you're effectively committing to some form of password storage, so whether or not "hard passwords" are pointless, they're just easier. I just use 1Password to generate strong 16char passwords because it's easier/quicker than "thinking up something random enough and recording it somewhere suitable".
Sure there's the "all eggs in one basket" problem with my 1Password database, but it's got a strong (~25char) pass phrase, and even then there's a class of passwords I store only on my head. My 3 banking passwords, my pgp key pass phrase, my root passwords, and my DNS registrar passwords.
One thing I think people often overlook is that your DNS registrar access credentials trump your email's two factor auth - if I can change your MX records, nothing you've done to secure your email account matters - I'll just get everyone to send your password reset requests to a mail server under my control…