A Case For Standardizing Password Security->
"One can rightly make the case that the ball is in the user’s court, and the only secure password is a unique one used once per site, managed through a centralized password database like KeePass or LastPass. And I think that’s a good case to make, but I don’t want to let service providers and software engineers off the hook just yet – I think we can do a much better job and I’d like to address three points in particular:
A strong and secure technical implementation for the storage of user credentials.
A password policy or ruleset that promotes the creation and usage of secure passwords.
And this is important: Always permit users to securely delete their accounts.""
Link to Original Source