

It doesn’t even have to be that long. 12-16 characters and it’ll be infeasible to brute-force for the foreseeable future. But unless you’re talking a high-value target like government, military, or executive suite at a company, no one bothers to brute-force anyway because there’s easier ways to gain access.
The biggest issue with password security is reuse and sharing. The most secure password in the world doesn’t mean a damn thing if you use the same email/password combination across a hundred different websites, because all it takes is for just one of them to suffer a leak and now your credentials are in a dump with millions of others that can be bought for a song and a dance.
This is why it’s imperative to use 2FA for your most important accounts, because it can mean the difference between an attacker getting access and hitting an error page and trying the next poor fucker’s credentials instead.
But also, no one wants to try to remember a hundred different unique passwords so it’s also a good idea to use a password manager. Chrome and Firefox both have them built-in (note that Firefox stores passwords unencrypted on disk unless you set a master password!), but there’s also services like OnePass or Bitwarden that have stronger guarantees.





Source?
Source?