It's kind of ironic that the only practical way of following all the common advice given about password security is to use long randomised passwords per account, stored in a password manager, because those passwords would otherwise be impossible to remember.