I solved this problem in my deterministic password manager: passwords are generated from a keyfile, which is encrypted with your master password. This means that if someone gains access to your master password, they can't do anything without the keyfile, and likewise if someone gets access to the keyfile without the master password. Also, changing the master password becomes a simple operation (the keyfile is simply re-encrypted, no need to change site passwords). Since passwords are generated deterministically, the keyfile needs to be synced only once to all devices, after that you have syncless operation. https://github.com/baobabKoodaa/baopass