> People are often more secure with less stringent security measures that they actually use. History has shown otherwise countless times. Yes, they get a *temporary* false sense of security, but then the house of cards always comes down and everyone acts all shocked that *they* had an online account hacked, or were hit by ransomware, or lost data on a thumb drive they never backed up. > Keeping credentials on paper locked in a safe is my idea of bad security for credentials that you use with any frequency. That's a straw man of your own creation. My point was that *some* data is best curated for security by making it impossible to access via a computer. To argue otherwise makes your motives suspect. I mean, where would you recommend someone keep their password manager's master password? > Finally, accessing the credentials is painful. Yes. That's the point! Memorize it if it's that important and often used. Otherwise, be mindful of *how* you do and don't limit access to different sets of credentials. > Keepass, by the way, is not a proprietary program Never said it was. I was pointing out that password managers *in general* are opaque to most of their users. A vulnerability discovered tomorrow could fully expose your basket full of eggs, and you have to thoughtfully act with that expectation. Likewise, you should plan for the hit-by-a-bus scenario so that you *can* allow access when appropriate. The world does not revolve around Keepass. So, no, maybe proper security is not a "logic" you can get behind for everyone. But *your* kind of logic . . . I mean . . . r/LeopardsAteMyFace d2dce21a33b556fd1a89050cb815d95e9620d9a03a8e259f59ea9e2663f895c2