A stranger on a forum corrected my password manager setup
Last fall I posted asking about storing backup codes, and someone pointed out that I was keeping them in a plain text note on my phone. They said if my phone got stolen, that defeats the whole point of 2FA. I moved everything into a KeePassXC database stored on a USB drive that stays in my fire safe at home. It took about 20 minutes one evening to set up, and I also added a YubiKey for the important accounts. Has anyone else had a similar blind spot that took an outsider to notice?
My blind spot was keeping my master password on a sticky note stuck to my monitor for like two years. Real smart, right? I finally moved it when my roommate pointed out that anyone walking by could just read it. Now I use a YubiKey too and the sticky note is long gone.