No password manager sounds like an awful idea, who can memorize all their passwords?
How can I keep passwords on 2 computers, an iPhone and iPad all in sync?
No password manager sounds like an awful idea, who can memorize all their passwords?
How can I keep passwords on 2 computers, an iPhone and iPad all in sync?
Firstly, companies change logos, change names, force password resets or your password will leak in a breach. How does this system accommodate those scenarios?
Also, once a few of your passwords are in data breaches, anyone who wants to target you can derive your admittedly less complex formula.
It is not out of the question that there already is or will be technology to compare multiple passwords from the same person from different leaks and derive the formula.
It's true that's a hypothetical attack vector.
In practice, so few people use this approach that you're not going to see a general-purpose deployable attack suite based on this principle. It'd be useful for a targeted attack, but if you're under a persistent, targeted threat there are better tools (spear-phishing, social engineering, physical compromise, etc.).
If someone breaks into my home, they’ve got it. But that’s not a threat model that scales, so it’s not a major concern to me.
But people are often away from home and want to log into websites and apps from their smartphone. A physical password book sitting at home is useless for that very common scenario. That "login from anywhere" is the typical motivation of gp's comment: "How can I keep passwords on 2 computers, an iPhone and iPad all in sync?"
And again, to take it a level further -- I would absolutely use a company's software under one, and only one condition -- indemnity/warranty.
Any company that is willing to go "If you get breached, we will pay for the harm" can absolutely take my money.