Passwords should just be random numbers, and services should provide a suggested password on the sign up pages. Here's a 128 bit password: CR4EOJ5ZYQRKCGQV4OLN2ZRFS. Better than all that is public key authentication.
We need a push like it happened for HTTPS, which became widespread in less than a decade, but that basically means Google has to push for it.