A pentester in Denver told me my password manager was backwards, took a day to change
I had everything auto-filling and never locked it down, he said "you're just handing out the keys" and showed me how to enable a master password timeout plus a hardware key for sensitive sites. Took me a full Saturday to redo all my logins, but now I actually control when it unlocks. Anyone else run with the defaults for years before getting called out?
Did you actually test the timeout before you trusted it? I ran mine for two years with autofill wide open, never thought about it. Now I use a five minute lock and my YubiKey for banking, that's it. The rest can wait. Setting it up sucked but it's done. Better than finding out the hard way.