Great, there goes my NXT experience. Hope you all do well. I have myself to blame.
Ok, we need good random generators included in all clients.And when you create a new wallet, it should pre-fill your passphrase with 40 or something long random string.
And won't allow you to continue, until you click a small checkbox "Yes, I saved this passphrase somewhere".
+1000.
...saved this passphrase somewhere...ON PAPER.
And a checkbox that they did a SHA-256 file check.
And a strong warning about keyloggers.
NXT is so security critical that we have GOT to do some serious handholding education for new users during the initial client setup!!!