I guess scrypt makes it much harder in memory requirements to bruteforce dictionaries and famose phrases/documents although still risky with keyloggers.
The most promising web wallet i've seen so far is https://greenaddress.it which seems pretty much like "Electrum" online but with two factor which in theory means a local keylogger can't steal your bitcoin.
Brain wallets should never be used.
Even experts fail at picking phrases with enough entropy.
Full stop.
You should be very carefull with your Bitcoin.
I would go with one of the zero trust multisignature wallets because I like 2factor and I don't like the idea of some malware taking the funds away at will when it finds a key in memory.
Even better with an anti tampering hardware wallet talking to a service provider for 2FA for most security