Earlier quoted context omitted.
It might have been a convenience thing back when there were only a few sites on the Internet but it's unreasonable, and just not practical to expect users to memorize several hundred, good, unique passwords for all the websites and apps they'll use in their modern digital life. Login with Google/Facebook/Apple/auth0 help mitigate the number of passwords to remember, but then you are beholden to that company. Not all…
My bigger worry is less getting hacked and more losing access to the password manager: If I use an online one, I'm once again dependant on a third party that can change their terms (or have an outage or get hacked) tomorrow; if I use an offline one, I have to manage a password database which has to be backed up, synchronized across devices, etc. If I use a new device, I cannot log into any account if I don't have an…
99.9% of people are going to be unable to remember a reasonable number of variants that aren't trivially deterministic and once things are very similar to another its increasingly easy to confuse them.
You can sync your encrypted password vault between local devices and a remote resource which has access to the vault but not the key for same. At that point is very very hard to get pwned or lose access to anything. This was a solved problem 20 years ago.