Most password advice focuses on the wrong thing: complexity. What actually makes a password unbreakable is its length. A password like "P@r0l4!" looks complex to the human eye, but it is eight characters long and uses well-known substitution patterns — which is exactly what attack software tries.
Four ordinary words such as "blue door eight olive", on the other hand, are easy to remember yet practically impossible to crack by trial and error. Length always wins.
The real danger: using the same password everywhere
No matter how strong your password is, the most common way accounts are taken over is this: a site's database leaks, and the e-mail and password pairs in it are tried on other sites. Every place where you used the same password falls at the same moment. That is why the rule "a separate password for every account" matters more than how complex the password is.
Password managers
There is no way to keep separate passwords in your head — and there shouldn't be. That is what a password manager is for: you remember a single master password and it holds the rest. Even the one built into your browser is better than nothing.