In this guide
- The problem a password manager actually solves
- How a password manager works
- Choosing one
- Setting it up: the first hour
- Migrating: the realistic plan
- Habits that make it stick
- Common worries, answered honestly
- What to do next
The problem a password manager actually solves
Most advice about passwords focuses on strength. That is the smaller half of the problem. The larger half is reuse.
The average person has well over a hundred online accounts. Nobody remembers a hundred distinct strong passwords, so people do the only workable thing: they pick two or three good ones and use them everywhere, with small variations. This feels sensible and it is the single biggest weakness in most people's security.
Here is why. When any one of those hundred companies is breached — and over a long enough period, some of them will be — attackers recover the email address and password pairs. They then run those pairs automatically against hundreds of other services. Your bank, your email, your cloud storage. This is called credential stuffing, it is entirely automated, and it does not require anyone to be interested in you specifically. It works purely on volume.
A password manager breaks that chain. Every account gets a long random password you never see and never type. One breach costs you one account instead of your whole online life. That is the entire value proposition, and it is worth the setup effort.
How a password manager works
You memorise one long passphrase. Everything else lives in an encrypted vault, unlocked by a key derived from that passphrase. Because the encryption key is derived on your device, a properly designed password manager cannot read your vault — the provider stores a blob of encrypted data they have no way of decrypting.
Day to day, it works like this. You visit a login page. The manager recognises the site and offers to fill your details. You approve with a click, a fingerprint, or a face scan. When you sign up somewhere new, it offers to generate a random password and save it. After a week or two, you stop thinking about it.
There is a security benefit here that people rarely notice: a password manager matches on the exact domain. If you land on a convincing phishing copy of your bank's login page, the manager will not offer to fill it, because the domain does not match. That silent refusal is one of the better anti-phishing defences available, and you get it for free.
Choosing one
The differences between reputable options matter less than most comparison articles suggest. Any of them is a large improvement on what you are doing now. What to look for:
- End-to-end encryption, so the provider cannot read your vault. This is standard for the well-known options and worth confirming.
- Independent security audits, published rather than merely claimed.
- Apps for everything you use — your phone, your computer, your browser. A manager you cannot reach on your phone will not be used.
- A clear history around incidents. Every long-running provider has had something; what matters is how openly it was handled.
- An export function, so you are not locked in if you change your mind later.
The built-in managers in your browser or operating system are a reasonable middle option, and considerably better than reuse. Their weakness is that browser-stored passwords are a primary target for information-stealing malware and can often be extracted quickly from a compromised machine, and that they tie you to one ecosystem. A dedicated manager is the stronger choice if you are willing to install one.
Avoid anything you have not heard of that markets itself primarily on being free, and avoid spreadsheets, notes apps and documents. An unencrypted file called passwords is worse than reuse, because it fails completely rather than partially.
Setting it up: the first hour
1. Create the master passphrase
This is the one thing you will memorise, so give it real thought. Use four to six random unrelated words generated by a tool rather than chosen by you — our passphrase generator does this in your browser. Something like anchor-violet-kettle-summit.
Do not base it on a quote, a lyric, a family name, or anything meaningful. Do not reuse a password you have used elsewhere. Write it on paper and keep it somewhere safe for the first fortnight while it settles into memory, then destroy the paper once you can recall it cold for several days running.
2. Turn on two-factor authentication for the manager itself
Do this immediately, before you put anything in the vault. The vault will become the most valuable target on your account list, so it deserves the strongest protection the provider offers.
3. Save the recovery kit
Most managers issue an emergency access code or recovery key. Print it. Store it with your important documents, not on the device you use to access the vault. If you lose the master passphrase and have no recovery kit, the vault is gone permanently — that is a consequence of the encryption working correctly, not a flaw.
4. Install it everywhere
Phone, computer, and the browser extension. Do this before you start adding passwords, so you are never in the position of needing a password on a device where the manager is not installed.
Migrating: the realistic plan
Do not try to change a hundred passwords in one sitting. People who attempt this give up halfway and end up worse off than when they started, with half their passwords in a vault and no idea which. Spread it over a week or two, in priority order.
- Day one: your email account. Change it to a long generated password and save it. Your email resets everything else, so it comes first, always.
- Day two: money. Banking, payment apps, anywhere a card is stored.
- Day three: identity. Cloud storage, photo backups, your phone account, your domain registrar if you have one.
- Day four: social media. These get used to defraud your friends and family in your name.
- After that: as you go. Every time you log in to anything, let the manager save it, and change the password if it was one you reused. Within a month or two you will have covered nearly everything that matters.
Along the way you will find accounts you had forgotten. Delete the ones you do not use rather than importing them. An abandoned account is still a breach waiting to include your details.
Habits that make it stick
- Let it fill, do not copy and paste. Autofill checks the domain; copy-paste does not, so it loses you the anti-phishing benefit.
- When it refuses to fill, stop and look at the address. That refusal is information.
- Use the notes field for security question answers — which should be random strings, not honest answers — and for account recovery details.
- Run the built-in security check once a month. It flags reused, weak and breached passwords, which turns the whole clean-up into a short list rather than a vague worry.
- Set up emergency access for a partner or family member if the manager offers it. It sounds morbid and it saves enormous trouble.
Common worries, answered honestly
"Isn't it dangerous to put everything in one place?" It concentrates risk, yes. It also makes the risk manageable rather than distributed across a hundred sites of unknown quality, and it lets you defend that one place properly with a strong passphrase and two-factor authentication. The alternative is not better security; it is reuse, which fails silently and completely.
"What if the company gets hacked?" This has happened to providers. Because vaults are encrypted with a key derived from your passphrase, the practical consequence depends almost entirely on how strong that passphrase is. A long random passphrase remains secure even if an encrypted vault is stolen. A weak one does not. This is precisely why the first step matters so much.
"What if I lose my phone?" Your vault syncs, so you install the app on a new device and log in. This is why the recovery kit and two-factor backup codes need to live somewhere other than that phone.
"What if I forget the master passphrase?" Use the recovery kit. If you have neither, the vault cannot be recovered by anyone, including the provider. Memorise it properly in the first fortnight and keep the paper backup until you are certain.
What to do next
Pick one, set it up, and do your email account today. That single account is worth more than the rest combined, because it is the reset mechanism for everything else. Then work down the list over the next week or two.
Once the manager is in place, the natural next step is two-factor authentication, which protects you even when a password does leak. Between the two, you will have removed most of the realistic risk to your accounts — and you will never have to invent another password again.
Frequently asked questions
Are password managers actually safe?
A reputable one encrypts your vault with a key derived from your master passphrase, so the provider cannot read it. The realistic risk is far lower than the near-certain harm of reusing passwords across dozens of sites.
What happens if the password manager company is breached?
Stolen vaults remain encrypted. Whether they can be cracked depends almost entirely on the strength of your master passphrase, which is why it should be four to six random words rather than something you invented.
Is the password manager built into my browser good enough?
It is much better than reusing passwords. Its weaknesses are that browser-stored credentials are a prime target for information-stealing malware, and that it ties you to one browser. A dedicated manager is stronger.
How do I choose a master passphrase?
Four to six random unrelated words from a generator, not chosen by you and not based on anything meaningful. Write it down for the first fortnight while you memorise it, then destroy the paper.
Do I have to change all my passwords at once?
No, and trying to is how people give up. Do your email first, then anything financial, then update the rest naturally as you log in to each site over the following weeks.