This argument goes for password managers as well (which only work on the device that holds them).
My couple of password manager files encrypted and stored on Dropbox disagree with that one. (A couple of different ones because I like to segregate them by criticality. So I don't have to unlock the one with critical information most of the time. Reduces the attack surface.)
I can access them anywhere. Although I try not to access them on anything I don't have control over. For example: I memorize my dropbox password and my student login separately.
And it's a whole lot more secure to have a couple of long passphrases to unlock long generated passphrases for every site than to have a short password/passphrase for every site.
Comments
My couple of password manager files encrypted and stored on Dropbox disagree with that one. (A couple of different ones because I like to segregate them by criticality. So I don't have to unlock the one with critical information most of the time. Reduces the attack surface.)
I can access them anywhere. Although I try not to access them on anything I don't have control over. For example: I memorize my dropbox password and my student login separately.
And it's a whole lot more secure to have a couple of long passphrases to unlock long generated passphrases for every site than to have a short password/passphrase for every site.