Here are some of the latest guidelines I have picked up regarding password management:
1) Re-use an easy password for all non-sensitive data
It's impossible to remember all different passwords. Rather than re-using passwords on sensitive sites such as banking, etc, re-use passwords on all non-critical sites with something you can remember. This means you have less passwords to remember.
2) Be weary of password managers
Password managers are great, but it's easy for an attacker to find and if they can crack it, they get all your passwords.
3) Don't be afraid to write down a strong password
This is contrary to the age old belief, but it's better to use a strong, unique password and write it down than use a weak password. A hacker would need physical access to the paper and some context around where you might have used the password. This is better than using a weak password which millions of attackers are trying to break every day...
4) For password you use rarely, reset it on every use
For something you may only access rarely, it may be safer to set the password to something random that you'll never remember. When you need to access the site, use the password reset procedure which will email you a link to update your password. This is effectively the same as a one time pin.
5) Above all, ensure your email password is secure
As per 4 above, an attacker can usually reset most of your passwords with your email account. It doesn't help that many sites use your email address as the username.
One of the biggest risks with sharing passwords is that when one is compromised, you can't say for sure where it was compromised. It's difficult to hold a company to account if you use the credentials for many sites.
Some links:
http://www.pcworld.com/article/2455...mple-passwords-for-most-of-your-accounts.html
https://www.damballa.com/its-safer-to-write-your-password-down/