Everyone learned a long time ago that a password has to be complex: ONE BIG, one small, one number, one $penny$ character. And you need a different password for each account, don't you? I mean, it's crazy.
Someone gets out of the situation by using a password manager. But if this manager isn't cut off forever, who can guarantee, that the developer of this manager won't fetch all our passwords (together with logins and addresses, where to enter them)?
What to do?
By the way, we at bespale use trivial text notes, but we store them on extremely secure machines. Such a scheme is much safer than any manager, if only because the notepad has never yet been asked to go online.
Despite the fact that services have long been forcing users to come up with complex passwords (otherwise it's banal "not allowed" further), but making users come up with different passwords for different services - such technology does not yet exist. And this means that all of us, one way or another, use at best 2-3 complex passwords for all our accounts. Sound familiar?
Now let's do the math: