This means losing the master password is dangerous, so some people still choose to allow a host-side override where the business has some access, in order to enable account recovery in the case of a lost password.
I was _really_ disappointed when 1password dropped support for Dropbox sync and pushed everyone onto their storage. I'm uncomfortable, like you, with the truly single point of failure this way: I would much rather diffuse the storage and master credentials to separate parties.
And the real question is: how many of these logins require max level of security?
But if you're doing what most people do instead of a password manager, which is just re-use two or three passwords for everything, then you don't just have a single point of failure. You have dozens of points of failure. You're not letting "a business" know all your passwords, you're letting many businesses know your password, singular.
Also, password managers don't only come from "businesses". I use pass[0], which just gpg encrypts passwords in a git repo. If you're willing to set up sshd, git, and gpg on your devices, you can use pass.
That said I still recommend that people coming from the "old way" use something like 1Password or LastPass if self-hosted is not for them. I share your distaste for giving the keys to the kingdom to a single business, but it's better than the alternative. I trust LastPass more than I trust the weakest member among a random set of other businesses.
You don't. Password managers like Bitwarden are basically cloud storage for an encrypted blob that happens to contain your passwords wrapped up with a nice UI/UX and handle all the syncing for you between your devices. They don't "know" your passwords. They sync that blob and then all encryption and decryption is done on your device.
Not to mention with Bitwarden you can run your own server if you are comfortable doing so and don't want to rely on their servers.
> making it my single point of failure
So maintain backups of your encrypted vault. Also Bitwarden (which is what I use) doesn't require an internet connection to unlock your vault so even if you're stuck somewhere with no net access you can still access all your data. Export it, etc. It is 100% offline for use, internet connection is only needed to sync the encrypted blob.
---
IMHO the benefits of a good password manager with nicely integrated password management, history, generation, MFA, etc. far outweigh the drawbacks of your account being hacked.
I have over 300 logins in my password manager.
I only have to remember a few actually important passwords in my brain which makes life exponentially easier when logging in to so many different services each day.
To solve this, you can drop either one of the "memorability" or "uniqueness" requirements. Most people naturally drop "uniquness" and reuse the same passwords everywhere. Or you can use a password manager and drop the "memorability" requirement. It's safer and more usable to do the latter. Even writing it down in a physical notebook is an improvement over reusing the same password.
This is my concern as well. The whole idea of my passwords being in a black box that is tied to my hardware seems like a recipe for disaster if I am traveling and my hardware gets stolen, lost or destroyed.
(maybe there is something that I am failing to understand, but I've watched several videos that attempt to explain how a PW manager works and I've not found an answer)
- the master key derives from 1. your password, and 2. a long, random key that you type manually on each new device (so you can’t brute-force the password just from the server’s data, and you can’t decrypt the data just from your hard drive without the master password),
- none of these keys ever leave your devices (encryption and decryption happen client-side),
- the key is deleted from RAM, locking the vault, if you’re inactive for too long.
That makes some attacks hard. It will be defeated if malware can get 1. your secret key and 2. your master password. But in that case, your login cookies and what you type in login forms are vulnerable too, so there isn’t much difference.
That said, the model is generally broken and LastPass is near the bottom of the heap.
If you or they are not technically inclined, write them down on a piece of paper, stored safely.
If you are, encrypt a file or volume on your computer and use that.
I've done and advised this forever and each little story like this leaves me convinced that these ways, while not perfect, definitely beat all the others.
Frankly, I'd even avoid Dropbox here. No need; and slightly reduced threat model (e.g. you happen to pick a bad encryption scheme). Syncthing, if anything.