It's pretty easy to keep your password manager secure against the threats that most people actually face, and this removes the worst elements: password reuse and low-entropy passwords.
It's pretty easy to keep your password manager secure against the threats that most people actually face, and this removes the worst elements: password reuse and low-entropy passwords.
Password Managers are not the solution to the problem, they are a bandaid.
1Password is probably my favorite app/suite of apps ever. And I willingly shelled out for them. But most people balk at paying $.99 to remove advertising in mobile games, so I don't see this catching on.
(Plus sync, plus backups, plus...)
It can be, but it doesn't have to be. There's perfectly good password managers[0] which are free and open source. The problem in this case is getting people who aren't technically literate to use them.
Have your master pw compromised: have all passwords compromised
You're taking multiple failure points (which certainly has a higher chance of a failure than a single failure point) and replacing it with a single point, with lower chance of failure BUT with bigger consequences
The following is a password manager developed by Bruce Schneier:
Then don't.
I rely on similar passwords for non-important services, but important ones have an unique password/2FA
You're still vulnerable some attacks like keyloggers but I think your description downplays many of the benefits (mitm or a poorly secured remote database wouldn't expose your master password). There are other great features password managers are starting to add; letting you know how long ago you changed your password, informing you if you haven't changed a password after a site had been compromised, changing your password for you (each site is different and updating passwords is very time consuming).