I lost my email address once too but got it back after a few days of talk with adwords support ( was a gmail address ).
.
KeePass+Flashdrive is probably as safe as you're going to get.
As for always losing it, get one of the ones that has a keyring on it and stick it with your car keys. How often do you misplace your car keys, after all?
Change your passwords for Email, Paypal, BankAccount, etc... anything important on a regular basis. And make the passwords RANDOM!
I just got my yahoo, gmail, paypal and bank account hacked and now I'm officially in debt with no way of verifying anything because my email addresses don't exist.
Next for everybody touting 'secure password keeper software' it doesn't matter a shit. Most trojans capture keystrokes and form data (in addition to password stores on pcs) so essentially, whilst it might safe as soon as you go to use it on a infected pc you are owned.
With Keepass you don't keep entering your password though. the malware would have to record your clipboard to catch these - which I realize is not hard to do, but that is an extra measure.
Notice the items in bold? This is my username and password, in the clear and logged, gameover. Whats worst is that when the hackers parses this data to get the credentials they only need to look for the strings 'login=' & 'passwd=' to get my details.https://login.yahoo.com/config/login?
POST /config/login? HTTP/1.1
Host: login.yahoo.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: https://login.yahoo.com/config/login_verify2?.intl=au&.src=ym
Cookie: B=1vff4qd4cp73p&b=3&s=4m
Content-Type: application/x-www-form-urlencoded
Content-Length: 319
.tries=1&.src=ym&.md5=&.hash=&.js=&.last=&promo=&.intl=au&.bypass=&.partner=&.u=cj0n1ih4d3c9b&.v=0&.challenge=B0u0V0KOLVIbFWYMWm7JLPqmsGuA&.yplus=&.emailCode=&pkg=&stepid=&.ev=&hasMsgr=0&.chkP=Y&.done=http%3A%2F%2Fmail.yahoo.com&.pd=ym_ver%3D0%26c%3D%26ivt%3D%26sg%3D&login=blackhat&passwd=thishasbeencopyiedandpastedin
I've had this same pass for 7 years now... I use a variant of it for EVERYTHING (I can pull a segment of it out and use it for a site)
Not saying he would steal the $29.92 in your paypal