I recently looked into password managers myself after the MtGox leak. I tried 1Password and LastPass. While both do what they say--I found them cumbersome to use.
I settled on a scheme like this:
E-mail: Very strong, completely unique. 2-factor auth. If you have my e-mail, it's game over.
Bank: Very strong, completely unique.
The rest of the passwords I've broken down into tiers. I've memorized a password for each tier combined with a hashing algorithm stored in my head.
The theory here being if an entire tier gets compromised (someone figures out my hashing scheme), at the very worst I lose the entire tier.
This does keep me safe from automated attacks, but not if someone singled me out individually. Which in that case, I've got other problems.
This isn't perfect, but it gives me a couple of things I really value:
- Keep all passwords in my head
- Unique passwords on each site
- Tiered passwords so if someone figures out my hashing scheme, they only get that tier
I like the idea of password managers, but in practice they were too much hassle for me.