It'a aways a trade off between security and convenience. The best way I've managed to come up with is to use a password manager but then secure the hell out of it by using hardware keys as a second factor to access it, and only allowing getting around that with a printed out backup key. This way you have the convenience of all the passwords as you need them on verified devices, but strong security (+ inconvenience) i…
> secure the hell out of it by using hardware keys as a second factor to access it I did this, then my phone broke and I was the only one with access to a particular system at work. It was miserable getting back in. I think harder about how I set myself up now.
Most websites including financial ones fail on the second point. And it worries me because SIM swapping is real and does happen to people you know.