A password manager exists so that every site gets its own long random password that you don't remember and don't need to.
It generates passwords, stores them in an encrypted vault, fills them into forms, and, most importantly, refuses to fill them on a phishing site with a look-alike address. One password for everything is the leading cause of account takeovers: one site's database leaks and the password works for your email. A manager breaks that chain.
What a password manager does
- Generates 16 to 24 random characters that can't be guessed.
- Stores them in a vault encrypted with your master password; the service or cloud sees only encrypted data.
- Fills by matching the domain. On
yourbank-secure-login.comthe real bank's password won't appear, which is anti-phishing protection you can't replicate by hand. - Syncs between phone and computer.
- Warns about reused, weak and breached passwords.
- Often stores 2FA codes, notes, cards and files.
generates a long random password stores it encrypted fills it only on the right domain └─ the last one is the anti- phishing part: on a lookalike site it simply does nothing
Browser, cloud or local: three kinds of password managers
Built into the browser or OS: Chrome, Safari and iCloud Keychain, Firefox. Free, already installed, syncs through your account. Downsides: tied to one ecosystem, weaker protection against someone with your unlocked device, fewer features. A fine start, and far better than one password for everything.
Cloud services: Bitwarden, 1Password, Proton Pass and others. Work on every platform and browser, store the vault encrypted on their servers, support family sharing and shared vaults. Free tiers exist with the basics.
Local: KeePass and its variants (KeePassXC, KeePassDX). The vault is a file on your device; you arrange sync yourself (cloud, NAS). Maximum control, minimum convenience.
cloud synced for you, free tier on most local you own the file, sync is on you browser free, stuck to one ecosystem
How to choose a password manager
- Encryption on the device. The vault is encrypted before it leaves; the service can't read it. Look for "zero-knowledge" or "end-to-end".
- Open source or independent audits. Bitwarden and KeePass are open; closed ones should publish audits.
- All your platforms: phone, computer, browsers.
- Autofill by domain, not by site name.
- 2FA for the manager itself, ideally with a hardware key.
- Export, so you can leave if you dislike it.
- Breach checks against known leaks.
[ ] open source or a published audit [ ] encryption happens on your device [ ] export works, so leaving costs nothing [ ] a second factor on the vault itself [ ] a clear policy and jurisdiction
How to protect your password manager
The manager is a single point of failure, so:
- The master password is a long phrase of four or five words that you remember and never write down in the clear. Impossible to guess, easy to recall.
- 2FA on the manager is mandatory, preferably a key or passkey; why that beats SMS is in two-factor authentication compared.
- A recovery code or key in a safe place offline.
- Auto-lock after a minute of inactivity on phone and computer.
- Don't keep the 2FA codes for your email in the same manager unless the manager itself has strong 2FA; otherwise one breach gets everything.
1 the mailbox everything resets to 2 banking and payments 3 anything with a card saved 4 everything else, as you log in └─ change passwords as you go, not all in one evening
How to move passwords to a password manager
- Install the manager and its browser extension.
- Import passwords from the browser (Chrome and Safari export to CSV; delete the file after import).
- Each time you log in somewhere, replace the old password with a generated one. Start with email, banking, social media.
- In a month or two no reused passwords remain.
- Turn off password saving in the browser so there's one source of truth.
For a password without a manager, for a router or Wi-Fi, use the password generator.
cannot undo a breach that already happened does not replace a second factor cannot save you from a weak master password does not hide which sites you visit
What a password manager doesn't do
It doesn't protect against malware on the device that reads everything you type. It doesn't replace 2FA. It doesn't hide from the network where you log in; that is the VPN's job, covered in what can my ISP see. And it doesn't help if the master password is your birthday. It also doesn't solve handing a password to another person: in a messenger it stays forever, and how to send one so the link burns after reading is in how to send a password or file securely. A crypto wallet's seed phrase is a separate case: not a password but the key to all the money at once, and it's stored differently, see seed phrase: what it is and how to store it.
Migrating is easier to plan up front than to improvise.
Help me plan a move to a password manager.
Right now my passwords live: (in my head / in the
browser / in notes / in a file / nowhere).
Devices: (which). Roughly how many accounts:
(a guess).
What matters more: (syncing everywhere by itself /
the file staying only with me).
Give me a migration order: which accounts to start
with, how not to lock myself out on the way, and
what to do about the master password.
You may name products, but tell me the criteria so
I can choose myself.
In short
- A unique password per site is the only defense against database leaks.
- Browser-built-in beats nothing; an open-source cloud manager is the sweet spot; local is for people willing to tinker.
- Master phrase, 2FA with a key, recovery code offline.
404 VPN covers the network side: a shared network can't see where you sign in or what the manager fills, and the kill switch keeps traffic from escaping when the tunnel drops. Get started here.