Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
So make the manager’s password massive. There, that complete sentence just now is over 30 characters long and could literally be a password. You can double up security with a secret file that you must locate on your PC, in KeePass, at least. You can also add notes about entries, track more than just website accounts, etc. It’s just too much brainpower to remember individual websites’ passwords. All important ones have 2FA anyway.
Managers are local to your computer so you likely messed up big-time if it got hacked, whereas websites can get hacked entirely out of our control.
So make the manager’s password massive. There, that complete sentence just now is over 30 characters long and could literally be a password. You can double up security with a secret file that you must locate on your PC, in KeePass, at least. You can also add notes about entries, track more than just website accounts, etc. It’s just too much brainpower to remember individual websites’ passwords. All important ones have 2FA anyway.
Managers are local to your computer so you likely messed up big-time if it got hacked, whereas websites can get hacked entirely out of our control.