LastPass is a huge net gain in security compared to almost anything else you could reasonably do. As almost anyone online, I have a lot of different accounts. Aside from my main bank account and my email, I do not know any of them as they are long random single use strings.
LastPass has made certain compromises in security to give you more functionality. For example, you can log into their website and enter your master password, to retrieve any other password. This is bad since the browser can be compromised.
However, I trust the browser and LastPass more than I trust my ability to keep the passwords secure. There is no way that I am going to remember the 300 or so passwords I have stored in LastPass and I will certainly not be able to change them as fast as I sometimes have to.
I am not saying that LastPass is the end-all-be-all of security, but compared to what 99.999% of people are doing, it is a huge win. IMHO, your statements are spreading FUD.
> assuming that every place you use a password is both competent and honest (which is a stretch), the only way for someone to get your passwords is to compromise your computer. if they do that, and you use lastpass, then they have all of your passwords.
That assumption has been proven time and again to be completely false. As someone who had their BTC stolen while using what would be considered a secure password, I can say that password cracking against a stolen database dump is not a theoretical threat.
> for this reason I recommend writing your passwords down on a piece of paper you keep in your wallet or purse.
This goes directly against your initial point that you don't know when your passwords have been compromised. You have no idea when someone takes a picture of your password sheet :)