If I need to login to your site less than once or twice a year, "Forgot my password" is my password manager. Personally, I feel that the utility of me working to keep and maintain that information in a database for high availability is essentially zero. As a result, I store very few accounts overall and checking out as "guest" hasn't been a problem of any sort. There's like 10 critical things that I feel the need to…
I just use a crappy password. It's been leaked before. I don't care. If someone wants to take over my last.fm account that I haven't used in 3 years, sure go for it. The important accounts get a randomly generated password stored in my password manager. And the really important accounts only have half the password saved, I manually fill in the other half.
- Access to any of your accounts could make impersonation easier. You might not be the one who suffers from whatever they do. Or if they can assemble enough PII, you might unexpectedly have a line of credit taken out on your name.
- Many websites use some form of federated login, or a crossover kinda situation where you have a username/password login that is linked to eg a Google account. Access to the username/password account could open you up to an attack on the juicy targets.
Personally, I'd rather none of my accounts are easily compromised, but that's a pipe dream - it's not up to us to secure the services we use. So best thing to do is just use a good password.
It's easy these days to use a good password, though I acknowledge still tedious/impossible to update all of your services.