

You should not use lockscreen password as your master password. Chances are, your lockscreen password is much simpler than your master password. Reason why you can get away with it is because your mobile devices usually have some form of well-integrated isolated environment that can throttle brute force attacks. Your password managers probably cache your vault offline, which may be vulnerable to brute force attacks unless it utilises TPM in some way. Same goes for FDE. Online vaults probably have some sort of rate limiting so that isn’t much of an issue.
One thing I strongly recommend is being realistic with your goal. Current scheme seems a bit too paranoid.


That’s fine as long as you’re okay with typing it in every now and then. I would find it tedious to be honest. Past a certain point, additional security is meaningless.