security is a lot of risk management. you'll never be 100% secure; you have to balance security with the user experience. for password managers, it allows you to create and manage secure passwords under one roof. it's not reasonable to expect users to memorize unique 14+ character passwords with special characters and numbers that they also have to rotate every 90 days or so for all their accounts. without password managers, most users would just use "thisismybirthday12345$" for every account.
LastPass incident aside, most of these services can be pretty robust. bitwarden for example requires MFA, and they can't even open your vault without your password. so if you forget it, you're SOL.
and yeah, like I said, it's all risk management. even newer options like passkeys have their own risk. what if someone with your biometric data steals your device?
Allmind exists for all mercenaries.