Keepass if you want passwords off the cloud, otherwise lastpass. Have a different password for everything. Add MFA when you have the option. Highest level of password security needs to be on your email since that it most likely how you can reset all the other passwords. Don't stay logged into things and don't be logged in to too many things at the same time, especially social media. The more integrations it has the less other things you want to be logged in to when using it. But really the biggest attack vectors for anyone that is not on DS radar is social engineering. Do not jump to change a password if you get an email about something, and same goes for highly publicized data breaches (I know this sounds counter-intuitive, but if it is in the news you are either already fucked, or reauthenticating with a possibly compromised authentication system, do not act until you are notified). Do not verify yourself on social media and upload all the documents one would need to assume your identity. Use apps and your mobile as little as possible when using authenticated services. Pay a man in a trench coat with cash in a dark alley for a sealed yubikey if you really hate yourself.
Keepass if you want passwords off the cloud, otherwise lastpass. Have a different password for everything. Add MFA when you have the option. Highest level of password security needs to be on your email since that it most likely how you can reset all the other passwords. Don't stay logged into things and don't be logged in to too many things at the same time, especially social media. The more integrations it has the less other things you want to be logged in to when using it. But really the biggest attack vectors for anyone that is not on DS radar is social engineering. Do not jump to change a password if you get an email about something, and same goes for highly publicized data breaches (I know this sounds counter-intuitive, but if it is in the news you are either already fucked, or reauthenticating with a possibly compromised authentication system, do not act until you are notified). Do not verify yourself on social media and upload all the documents one would need to assume your identity. Use apps and your mobile as little as possible when using authenticated services. Pay a man in a trench coat with cash in a dark alley for a sealed yubikey if you really hate yourself.