My main problem with passwords is the limits that sites put on what I can set for a password.
I could not tell you how many times I reset my password using my password manager, then immediately log out, and log in using the credentials I just saved into my password manager, and they don't work, because the site is truncating the password to 15/20/whatever characters.
The number of times this limitation is not clearly stated, checked for, or even acknowledged by the site is too damn high.
I've made it a habit of testing a login after every password set/reset to ensure I don't have trouble with it in the future.
My password manager generates 32 character passwords composed of random alphanumeric characters by default. I usually don't modify it unless I hit a restriction, or its a site I'm particularly concerned about getting penetrated (in which case I increase the number of characters).
I don't mind sharing that because bluntly: anyone reading this, good luck figuring it out. The permutations is something along the lines of (26*2+10+(special characters))^32... Which is 3.5239... * 10^60... Otherwise known as 3.5 novemdecillion.