Re: "passwords ... copied from the original email. Marginally better than post-it, but only just..."
Exactly. Post-its are bad physical security but, unlike password lockers, cannot be hacked remotely.
Though I suppose you could put your password locker on a separate, air-gapped system.