You should most likely generate a unique one for each website, but I doubt any attacker is going to go to the trouble of capturing that once and trying it again as a security answer elsewhere.
I use a password manager…. Generate a random string at 36 characters and then back off to whatever they’ll accept.
The number of idiots forcing less than 24 characters for things like that's… way too damn high. (Probably preaching to the choir here but there was an issue with windows screwing with the encryption or something “requiring” 24 instead of 12.)