There are a number of things to consider when you select passwords for your online accounts (e.g. banking, email, shopping sites, social media, etc.). Here are some of them:
Priorities
Know which sites will hurt you the most if they are compromised. This will help you balance the risk/inconvenience equation as you consider how many and how strong of passwords you are willing to commit to memory. Here is my order:
2) Any site where someone may be able to obtain information that would help them gain access to #1 (e.g. email, online file storage or backups like Dropbox or Carbonite etc.)
3) Social Media. This could come before or after Shopping depending on how much of your "life" is on social media and how you use it.
4) Shopping sites. I put them lower on the list simply because you typically have recourse for unauthorized use of credit cards you have stored on shopping sites.
5) Other (e.g. website subscriptions for games or other online services)
Password Strength
* A minimum password length of 12 to 14 characters if permitted
* Generating passwords randomly where feasible
* Avoiding passwords based on repetition, dictionary words, letter or number sequences, usernames, relative or pet names, romantic links (current or past), or biographical information (e.g., ID numbers, ancestors' names or dates)
* Including numbers, and symbols in passwords if allowed by the system
* If the system recognizes case as significant, using capital and lower-case letters
* Avoiding using the same password for multiple sites or purposes
* Avoiding using something that the public or workmates know one strongly likes or dislikes
In a perfect world, you would have a different password for every account. If this is not your world, consider this approach:
* Have a unique password for each priority #1 online account.
* Have a unique password for each priority "level" thereafter (e.g. #2, #3, #4, and #5).
* If using a password for multiple accounts, be sure that it is strong and complex so 1) it is not guessed and 2) it meets the password strength requirements of each website.
The Password Manager Option
If you have a lot of online accounts, a password manager service (e.g. lastpass.com) can help make it practical to implement all of the password recommendations above. Many of these services generate complex passwords for you, save them, and then automatically retrieve and fill in the username and password when you go to the associated account's login page. This means that if you can remember 1 really strong password, you don't have to remember the rest. The benefit is that you are protected from weak passwords across all of your different online accounts. You are, however, trusting a single vendor's security systems, procedures and protocols to retain all of your important website credentials.
If you use a password manager, here are some suggestions on how to mitigate this risk:
* Do not save your #1 priority (and possible #2 priority) passwords withing the password manager.
* Never save the password manager password anywhere on your computer. Make it prompt you when you launch your browser.
* Be sure your computer locks after inactivity and you have a strong password on your computer so someone can't walk up to your computer and access your online accounts.