Aha, now it's getting a bit clearer...
Yes, obviously. Even if you have the most complex password on the planet, it means absolutely nothing if you just write it down on a scrap of paper and hand it directly to an attacker.
Okay, a few points. First off, never open suspicious links, especially when they come from shady sources. Every single time before you log into a site, check the URL in your browser. For example, if you want to log into Reddit, the domain at the top should be reddit.com, not something else. Where do you find the domain in the URL? See where I've highlighted it in red here:
Code:
That is the domain. It’s the part between those two slashes—the right side of the first slash up to the second dot from the right. If you are logging into reddit.com, that specific spot must say reddit.com and nothing else.
As for cookies being stolen, honestly, I don't know much about that. I don't think a cookie can just be snatched like that, but I'm not entirely certain, so I won't dwell on it too much.
But one thing is for sure. Your password won't be sitting in your cookies unless you check "remember me" or something similar during login. So, just clear your cookies and don't use auto-login; then there won't be any passwords stored in them.
One more thing. If a website itself is poorly built (like some old forums), and it doesn't have SSL during login (meaning it uses the https protocol instead of http), someone can eavesdrop and intercept your password while you're sending it from your computer to, say, a forum's server. There isn't much you can do there, since it depends entirely on the site and its level of Security. Just know that any site you log into that doesn't start with
https, is a potential danger.
And another thing. Don't blindly install programs you download from the internet from unverified sources. Someone could easily send you a keylogger—a little program that records every single keystroke you make on your keyboard and sends it to someone else.