Sure, a long password won't save you from a phishing attack but 2FA can go a long way towards that. They being said, I have seen sophisticated attacks which do a login live while you supposedly put in your OTPs.
Long passwords are for protection against brute force attacks, and using a password manager ensures that if one account is compromised, your other ones aren't. If you force users to type in a memorable password, then they'll often revert to using either the same one or simple variations on it which would be easy to brute force or dictionary attack.