03-31-2021, 02:30 PM
The OP password wasn't compromised because it was simple. It was compromised because it was hacked where it was stored. It could have been a mile-long string of random characters. The complicating factor was using it on multiple sites. XKCD's method would be fine, but you'd still need a different one for each site.