Great tips, especially on avoiding the pump and dump groups.
I personally use and recommend pass for password generation and storage, its simple and effective - encrypts your passwords with your gpg key and stores them in a local git repository.
My other must-have IMO is QubesOS , letting your completely isolate all the components of your system into separate virtual machines. Steep learning curve, but 100% worth the effort.
Hope these are useful for someone.