If you reuse the same handful of passwords across multiple sites, or you rely on your browser's "remember password" prompt as your entire security strategy, you're carrying more risk than you probably realize. A single data breach at one of those sites can expose credentials that unlock several of your other accounts. A password manager fixes this by generating and storing a unique, strong password for every account, so a breach on one site stays contained to that site.
What a password manager actually does
At its core, a password manager is an encrypted vault protected by a single master password. It generates long, random passwords for each site, fills them in automatically, and syncs the vault across your devices. Good ones also handle two-factor authentication codes, secure notes, and flagging reused or weak passwords across your accounts.
What actually matters when choosing one
End-to-end encryption
Your vault should be encrypted on your device before it's ever sent to the provider's servers, meaning the provider itself cannot read your stored passwords even if their servers were compromised. Every reputable password manager does this โ but it's worth confirming in their security documentation rather than assuming.
Cross-platform support
Check that the manager has a genuinely good app (not just a barely-functional one) for every platform you actually use โ browser extensions for Chrome, Firefox, and Safari, plus native apps for your phone and desktop OS. A password manager you can't easily use on your phone will get bypassed the first time you're in a hurry.
Emergency access and recovery
Because the vault is encrypted with your master password, losing it can mean permanently losing access to everything stored inside. Look for a manager that offers a documented account recovery process or an emergency access feature that lets a trusted contact request access after a waiting period โ this matters more than people expect until they need it.
Local vs. cloud-synced vaults
Most password managers sync your vault through the provider's cloud servers, which is convenient but requires trusting their encryption and security practices. A smaller number of tools (like KeePass and its various clients) store the vault as a local file you sync yourself, using a service like Dropbox or Syncthing. This gives you more control at the cost of more manual setup.
Built-in browser password managers: good enough?
Browser-based password managers (in Chrome, Safari, Firefox) have improved significantly and are a real step up from reusing passwords. Where they typically fall short compared to a dedicated app is cross-browser support (a vault saved in Chrome doesn't help you in Firefox), advanced sharing features, and security auditing tools that flag weak or reused passwords across your entire vault. If you're just getting started, a browser's built-in manager is far better than nothing โ but a dedicated app is worth the switch once you're managing more than a handful of accounts.
How to migrate without losing access to anything
- Export from your current source first. Most browsers let you export saved passwords to a CSV file before you start โ do this as a safety net even if you plan to add accounts manually.
- Import into the new manager. Nearly every password manager supports importing a CSV in a standard format, and most publish specific instructions for importing from each major browser.
- Change your most important passwords, not all of them at once. Prioritize your email account (since it can reset most other passwords) and financial accounts. Rotating every single password on day one is unnecessary and easy to abandon halfway through.
- Delete the CSV export securely once you're done. A plaintext file of all your passwords sitting in your Downloads folder defeats the purpose โ delete it and empty the trash afterward.
- Turn on two-factor authentication for the vault itself. Your master password protects everything else, so it deserves the strongest protection you can give it.
This article is educational and does not endorse a specific paid product. See our Disclaimer for how we approach security recommendations.