Update: A security guy at a meetup told me my password setup was backwards, and fixing it was easier than I thought
I went to a small cybersecurity meetup in Columbus back in March and after the talks I ended up chatting with this older guy who does incident response for a hospital network. I mentioned I keep a password manager but I still reuse a few passwords for stuff like my email and my bank because typing the long ones is annoying, and he just looked at me and said that's the exact opposite of what you want to do. His point was that my email is basically the master key to everything since every reset link goes there, so that should be the strongest one, not the one I'm lazy about. He also said I should turn on two factor for email first and worry about the other accounts after. I went home that night and changed my email password to a long random one and set up an authenticator app instead of text codes, took maybe 20 minutes total. Then over the next two weeks I worked through my bank and a few shopping sites. It sounds small but it honestly felt like a win, and I'm not someone who's into this stuff as a hobby. Anyone else have a moment where one random comment made them redo their whole setup? Curious what you'd fix first if you were starting over.