When your typical installation uses a few rounds of MD5 or SHA1 (I have nothing to back that up other than having seen it over and over) and bcrypt is no where to be found, the last defense you have is a long and reasonably complicated password.I refuse to use Citibank online for just this reason.Also, obligatory XKCD.