The haveibeenpwned description says password hashes are md5, which sucks. But phpBB has used bcrypt by default since version 3.1 (2014)... I wonder if all the hashes are md5 or only those for older accounts?
Impacted as well, but I'm happy to be part of it. Either they'll crack an old password or, more likely, this is a new style password and they waste a lot of cracking time on it. Using a password manager for everything except a few offline things and my bank account was definitely the right move.
Same as for my master password: a randomly generated, memorized password.
The trick to remembering them is to use them regularly. This is also why I don't use a passphrase: a password is much shorter and less frequently typo'd, thus less annoying for frequent use.
No, it's real. It used to be prominently on the site sidebar, but it got very big around the time xkcd first got popular, and the link was subsequently removed. After that, you had to know it existed and just go directly to forums.xkcd.com, so the only people who knew of it were generally the people who were early xkcd readers or people invited by them. Imho it's one of the better open "offtopic" discussion forums on the web, partly because of insular culture trending towards thoughtfulness.