Don't remember to use the Passphrase, but should not be necessary for local passwords, I think it's just for Sync.
You are right about the needing of a 2 steps authentication method or to use a personal question, don't know if has been suggested, but should exist a warranty to recover your data even forgetting your Passphrase.
You can search if exists or create a new topic.
At the other hand,
take a look at KeePass, despite your browser's choice will keep all your passwords save, even for local machines, routers, ISP's, credit cards data...
You'll need to remember fewer passwords and it has extensions for browsers and apps for mobile devices - despite they are made from unofficial devs -.