Some sites have strong requirements. E.g.
Your new password must:
be at least 8 characters long (longer passwords are more secure)
contain at least 1 uppercase character
contain at least 1 lowercase character
contain at least 1 numeric digit
contain at least 1 of these special characters ~ ^ * _ ? \ . / ! + - { } [ ]
contain no spaces
I am a layperson (i.e. not familiar with security matters). Because these passwords are so damn hard to remember, I often, perhaps foolishly, record such passwords down, often digitally at various places, on my Windows desktop, in my emails, in some Notes app on my phone, etc.
I am probably not alone. So is it possible that because of user behavior similar to mine, these supposedly strong passwords are actually counter-productive?