Your own memory.
More precisely, create pass phrases (emphasis on phrase meaning: multiple words) based on certain characteristics only known to you that are relatively easy to remember by you and you alone. One trick is to use a common base phrase and then based on the service/app etc. you pick some characteristics of it to enhance the base so your full password would be [base-phrase]+[your-service-specific-parts]. Kind of like semi-analog version of a password and a password salt. Of course, if someone cracks your base phrase you are SOL so even that is not foolproof.
Either that or invest in memory palace techniques to make yourself supermemory so you remember every random password like yesterday.
Or third: get whacked in the head real hard so your brain rewires itself and you develop photographic memory and never forget a thing (yes, this one is a joke).
> Create a long, unique, random password.
> Save the site URL, the required userid, the password, and any other relevant things in a text file.
> Save all these text files in fossil.
> Password protect and save the fossil file with 7z.
When it's time to use a password, run a script to unzip the 7z file, fire up fossil, and expose the full set of password files, then access whatever I need.
When done, delete everything, leaving just the original 7z file.
Is it a little tedious and clunky? Yep. Does it work? Yep. Is it totally under my control? Yep.
Details
> Generate a 24-char password: gpg --gen-random --armor 1 18
> Fossil: https://www.fossil-scm.org/home/doc/trunk/www/index.wiki
My favorite feature being that the backend store supports git, allowing you to sync and backup for password to anywhere you can push a git repository.
Pass stores your keys encrypted using your gpg key. Having the master key on your yubikey adds additional peace of mind
Only place I never use my password manager is my smart phone, out of choice - i don't trust my phone
I never understand why people go all in on cloud based password stores or identify for that manner
With a whole host of alternate, compatible, implementations:
The vast majority of other passwords (e.g., HN's account), well, they are in plain text in some file on my computer. I really don't care about them.
I think a solution like Keepass with an encrypted file shared on common cloud file services would be great if we could trust the third party versions for phones.
Local password database storage
No cloud account
No login