https://github.com/kybernetikos/sinkless
I like it because there isn't any third party or service for me to trust, but I can still have unique complex passwords for each purpose. It feels pretty much the same as having them all in my head.
I'd like to make the UI work better in general, but in particular on mobile devices. But then I have many projects I'd like to make time for, and this one is probably usable enough for me for now.
Though it does syncing
Your reply however... stamps paranoid label on it :)
There seems to be a growing chatter on HN and elsewhere about how you can't trust free software because you didn't audit/write it yourself.
I'm not sure if people actually believe that or use it as a way to point out how they're smarter than other people.
Sure its possible that the free software contains something malicious, but such an attitude is not constructive. If you only used software you wrote yourself you might as well not use a computer. There are degrees of trust, balancing of risks, and free software has a much better reputation of not containing malicious code.
Basically, the story was that a program for grad research was inserting all kinds of nasty, anti-semetic things into text and it turned out the previous grad student had poisoned the compiler which was modifying the strings and was able to re-poison it every time through something else.
I forgot the exact details but it is an amazing read.
Then they aren't paranoid but normal folks, eh?
https://github.com/HainaLi/horcrux_password_manager
It is in JS at least. Underhanded C is likely an easier trick to manage.
Idk about other people but I find anything I don't find security holes in myself "as good" as anything I've written. I've got the same set of assumptions/blinders/competence either way.