Use a password manager and let it generate a different long random password for every site. Then you only need one strong passphrase, plus two-factor authentication on email and banking.
- Get a password manager. Several reputable ones are free and they are built into modern browsers and phones.
- One long passphrase to unlock it. Three or four unrelated words is stronger and easier than a short string of symbols.
- Let it generate everything else and never reuse a password anywhere.
- Turn on two-factor authentication on your email first, then banking, then everything else. Email is the master key that resets all the others.
- Prefer an authenticator app over SMS where it is offered, because SIM swapping is a real attack.
Reusing one password across sites is the actual mechanism behind most account compromises. When any one of those sites is breached, the attackers try that combination everywhere else, automatically.
Length beats complexity for resisting cracking, and uniqueness is what contains the damage of a breach. A manager is what makes both practical, because no human can remember a hundred unique long passwords.
Tipking is general household information, not professional advice. Test anything on a hidden patch first. Full disclaimer.