From a strict security standpoint, maybe all of this is true. But I see strong PR as a feature, not a bug...at least until password manager market penetration is closer to 100% than it is to 0%. Once you've adopted a password manager, you've limited the scope of potential abuse, and you've decreased the pain of recovering from abuse that does happen . Being forced to change passwords used to be a stressful problem fo…
These are security critical pieces of software. Like, AV, if the password manager makes it easier to compromise your access in bulk, that's a very very bad thing. This doesn't need to be targeted, just throw some JS into an ad and pwn up 100s of 1000s of accounts. That's actually worse.
1) Download two datasets from different massive breaches. You can find plenty of them with plaintext passwords on any torrent tracker.
2) Correlate email and password combos across datasets. Don't worry, you'll find 10s of millions of people who don't use password managers and reuse passwords.
3) profit
If you have reason to believe you're being targeted, any breach is a problem. But until my method no longer produces results, theres no reason to believe black hats will go through any additional effort to obtain the average person's creds.