"We need to give up trying to make people to care about password strength for stupid stuff like online forums. They don't. They shouldn't. Stress that it only matters for really important stuff like online banking, and to stop caring if your Twitter account password is insecure unless you have hundreds of thousands of followers."

You forget that hackers can break into the weak stuff to glean information to use in social engineering attacks to get at the stronger sites. IOW, weak passwords of any sort become gateways. So you must treat the most innocuous site just as much as your most secure one since one can open the way to the other, making the strongest site only as strong as the weakest one.

