If an account on an insecure website is using the same password as your email, bam they have access to your email. What else do they end up having access to? Pretty much everything. Secret questions are becoming more common to also verify you’re the actual account holder, but if someone were to get into your email they can grab other passwords you might have and try them at the ones they can’t get into.
See the problem there? So first and foremost, always use complex email password you use nowhere else. On unimportant sites like forums you can get away with using the same password and still be secure, if you want to be lazy. The only thing they can get into is other forums. Generally when people get passwords they’re not after forums because they don’t exactly know the ones you’ve registered at. The first thing they go after is your email. From there they try and pull up more and more stuff until it’s financial and then it gets sold on the black market.
Forums, blogs, and other databases are “hacked” all the time because a lot of PHP based software really isn’t all that secure. They have a lot of holes and people can grab the entire user database. If the database is unsalted it only takes a few days for GPUs to break the hashed passwords.
Make your financial stuff, email, and possibly facebook “special” in that you have 4 – 5 separate passwords if you can’t go all out and use a different password everywhere with LastPass or something similar.
