Password managers explained
One strong password to remember, unique passwords everywhere else – and a quiet side effect that blocks phishing automatically.
A password manager solves a problem that willpower cannot: you need dozens of long, unique, unmemorable passwords, and you are one person with one memory. The manager generates and stores them; you remember exactly one.
The part people miss: it also blocks phishing
This is the underrated benefit. A password manager fills in credentials only on the domain they belong to. Land on a pixel-perfect copy of your bank at a lookalike address, and the manager simply does nothing.
That silence is a warning signal you get for free, on every login, without having to inspect anything yourself. It is the most reliable phishing filter most people will ever have – see how to spot phishing for the manual version.
How it works
The basic model
- One vault, encrypted with a key derived from your master password.
- Zero-knowledge: the provider stores the encrypted vault but cannot read it.
- Generation: the manager creates long random passwords so you never invent one again.
- Autofill: it recognizes the site and fills the matching entry – and only that site.
- Sync: the encrypted vault travels between your devices.
Choosing a master password
Length beats complexity. Four or five random words are both easier to remember and far harder to crack than a short string of symbols.
- Do: pick unrelated words, aim for 20+ characters, make it something you can type daily.
- Don’t: use a quote, a song lyric, names of family members, or a password you have used before.
- Never: reuse the master password on any other service.
Getting started without a lost weekend
- Install the manager and its browser extension on the devices you actually use.
- Set the master password and store the recovery kit offline.
- Turn on two-factor authentication for the manager itself: how to set it up .
- Change your email password first – it is the master key to everything else.
- Then let it happen naturally. Every time you log in somewhere, let the manager replace that password. Within a month you are largely migrated.
- Set up emergency access so someone you trust can reach the vault if you cannot.
Worth being clear about
The risk people worry about – “all my eggs in one basket” – is real but much smaller than the risk they already live with. Password reuse is the actual attack that happens every day, at scale, automatically. A manager ends it.Browser store or dedicated manager?
The password store built into your browser is a genuine improvement over reuse, and if that is the realistic step you will actually take, take it. A dedicated manager adds things that matter over time: it works across browsers and apps, allows secure sharing within a household, warns you when a stored password appears in a breach, and offers emergency access for someone you trust.
Either way, the decisive move is the same one: stop reusing passwords.
Frequently asked questions
Isn't it risky to keep all my passwords in one place?
It is far less risky than the alternative, which is reusing a handful of passwords everywhere. A manager’s vault is encrypted so that only your master password opens it, and it removes the single biggest cause of account takeovers – reuse.
What happens if I forget the master password?
With a properly built manager, nobody can recover it – not even the provider. That is the point of the design. Choose a long passphrase you can remember, save the recovery kit offline, and set up emergency access for someone you trust.
Is the password manager built into my browser good enough?
It is much better than reusing passwords, so it is a reasonable starting point. A dedicated manager adds cross-browser use, secure sharing, emergency access and breach monitoring – and it is not tied to one browser profile.
Topics: Passwords