> 4. Switch to Google Chrome.
Can one configure Chrome to not be a data-sucking kraken?
> 7. Disable cloud-based keychain backups.
That backup is encrypted, I'd hope? So, is the problem that getting hold of a cloud-backup facilitates off-line attacks on the encryption key?
I remember Filippo (FiloSottile here) publishing his encrypted private PGP key [1] (back when he was still positive on PGP). If that's safe, how is this problematic?
> 10. Install a password management application that doesn't store your secrets in the cloud.
Same question as 7. My understanding was that most password manager vulnerabilities have been related to browser integration, so that is the first thing I'd switch off.
[1] https://blog.filippo.io/on-keybase-dot-io-and-encrypted-priv...