As for now:
don't care about user experience, meaning that time spent reading, typing, memorizing password.
not thinking about quantum computing attacks.
8 characters good, 24 characters better, 1000 characters best?
As for now:
don't care about user experience, meaning that time spent reading, typing, memorizing password.
not thinking about quantum computing attacks.
8 characters good, 24 characters better, 1000 characters best?
It's not worth it.
The security of the password cannot be stronger than the security of of the hashing algorithm used on the server to store your password. The password you used, no matter how long, are going to be hashed and stored in a fixed size hash. Pretty much all password hashing algorithms in common use are 256-bit or less, so using longer password than that mathematically won't give any additional security.