Passwords need at least 12 characters with upper and lower case, a number, and a special character, and known-common passwords are rejected outright, enforced server-side, not just in the browser. Add two-factor authentication on top and account takeover gets structurally hard, enabling 2FA.