http://www.schneier.com/blog/archives/2005/02/the_curse_of_t...
I guess he means we all ought to be using encrypted key pairs and the like instead, or some other system not involving anything as guessable as a text word.
The only downfall is that sometimes I forget the answers, but I eventually get them right. :)
eg: what is your pet's name? qw9er8rty
So: "What is your pet's name?" n0tm4hp4s5w3rd-pets-name and: "What street did you grow up on?" n0tm4hp4s5w3rd-street
You still have to remember an arbitrary string, it is SLIGHTLY more accessible than mashing randomly, and certainly more secure than putting the real answer.
Keyloggers, seeing the password written down somewhere visible, or even having someone convince you to tell them the password (social hacking) are all very simple ways to get access to someone's account. These are all pretty stock-standard ways to get a standard web users password.
It's kind of like moving all your money from different dodgy international banks to one bank, and then having that bank robbed.
We're always going to have to compromise between security and convenience. Someone in the public eye should probably have been well over towards security already. It will be interesting over the next few years to see how big an effect this has on the average member of the public.
I have a feeling that we've yet to see the best practices for account recovery emerge.