Best practices for online passwords. It's kind of crazy how bad so many online services are about this stuff. Including tech companies.
Friends don't let friends: - Use their browser's password autosave, because it's trivial for anyone to recover it. See also: http://www.hongkiat.com/blog/how-to-retrieve-passwords-from-asterisks/
Excellent, detailed, slightly technical, highly scary article on password hacking.