This means that the most important password choice you can make is to have a completely different password on every site.
This means that the most important password choice you can make is to have a completely different password on every site.
Some prefer stuff like keepass that let's them store everything - i'm happier to rely on an algorithm.
Key point is to make using different passwords in different places really simple, so that people do it.
A software trojan, that can capture keystrokes, mouse movements, selected text, screenshots... Most certainly yes. :(
If you're storing them in lastpass, then they can grab them regardless.
If you're storing it in an encrypted partition, then they can grab them regardless.
Once somebody has access, it's game over.
There are still plenty of computers out there that are probably running vulnerable versions of Flash/Java etc. I imagine one of the biggest incentives to hack some random blog is to infest it with drive -by malware and compromise a bunch of machines if it has high traffic.
Also if you have a keylogger on a machine you can look for things that might be site admin passwords. So it wouldn't surprise me if there was a relatively symbiotic relationship.