hese days the only sane way to operate is with password managers and separate 2fa. One single strong password that is only used for accessing the password database. One secure device with the 2fa generation.
From there every site can use a long randomized password. With 16 random characters, pure alphanumeric is more than fine sufficient to be essentially impossible to crack. If one does get compromised, such as by being stored in plaintext, nothing else is. The only way to compromise the user is to compromise the password manager key which should never leave the user's computer.
Yes it does become a master key, but email already acts like that and a well implemented password manager is far better. The alternatives all involve bad passwords, password re-use, and passwords on post-its.
From there every site can use a long randomized password. With 16 random characters, pure alphanumeric is more than fine sufficient to be essentially impossible to crack. If one does get compromised, such as by being stored in plaintext, nothing else is. The only way to compromise the user is to compromise the password manager key which should never leave the user's computer.
Yes it does become a master key, but email already acts like that and a well implemented password manager is far better. The alternatives all involve bad passwords, password re-use, and passwords on post-its.