The average person has dozens of online accounts and a handful of passwords. They are not stupid; passwords are simply a bad system that has been asked to do too much. Remembering fifty long, random, unique strings is impossible, so people reuse favorites, add a number and hope. The weakness of that approach is simple: when one site is breached, attackers try the same email and password on others, and a single reused password becomes the key to many accounts.
A password manager is the standard answer. It creates and stores strong, unique passwords, fills them in for you and locks everything behind one master secret. It is one of the few security tools that improve both safety and convenience. This guide explains how they work, what differs between them and what to ask before you trust one with your logins. It does not guarantee any product’s security.
In brief
- A password manager lets you use long, unique passwords without remembering them.
- Your master passphrase is the one secret you must protect and never reuse.
- Turn on two-factor authentication for the vault itself.
- Check recovery and export options before you commit.
What a password manager does
A password manager stores your credentials in an encrypted vault. You unlock the vault with a master password, and sometimes with a fingerprint, face or security key on a device you have already set up. The manager can then:
- long, random passwords for new accounts.
- usernames and passwords on websites and apps.
- you to reused or weak passwords and, with some services, to passwords found in known breaches.
- other sensitive items such as secure notes, card details and documents.
- your vault across devices.
- selected items with family or colleagues.

How the encryption works, in plain terms
Reputable managers encrypt your vault on your device before it is stored or synced, using a key derived from your master password. In a well-designed system, the company stores only encrypted data and cannot read your vault. This is often called a zero-knowledge design. It means that if the company’s servers are breached, the attackers get encrypted data, not your passwords, though a weak master password makes that data easier to attack.
We cannot audit a vendor’s claims. Look for independent security audits, a clear description of the design and a record of how the company has handled past incidents.
Types of password managers
- Standalone cloud manager. How it works: Vault synced via the vendor’s servers. Strengths: Convenient, multi-device, easy sharing. Limits: Trust in the vendor and its security.
- Browser built-in. How it works: Saves passwords in the browser or its account. Strengths: Free, simple. Limits: Often tied to one browser or ecosystem; fewer features.
- Operating-system keychain. How it works: Built into the device ecosystem. Strengths: Seamless within one ecosystem. Limits: Less useful across mixed devices.
- Self-hosted or local-only. How it works: You store and sync the vault yourself. Strengths: Maximum control. Limits: You are responsible for backups, updates and security.
- Family or team plans. How it works: Shared vaults and administration. Strengths: Easy sharing and recovery. Limits: Higher cost, shared risk if mismanaged.
For most people, a reputable standalone manager or a trusted built-in option is a large improvement over memory and reuse. Self-hosting suits technically confident users who accept the responsibility.
Features worth comparing
- Does it work on your phone, laptop and browser?
- It should work reliably in apps and sites.
- including security keys.
- What happens if you forget your master password? Some designs offer no recovery, by design, which is secure but unforgiving. Others offer recovery methods with their own trade-offs.
- letting a trusted person access your vault in a crisis.
- for families and teams.
- Check that you can leave with your data.
The master password: the one thing you must get right
The strength of the whole system depends on the master password. A good one is long, unique and memorable to you. Many security experts suggest a passphrase made of several unrelated words, which is easier to remember than random characters and strong when long enough. Never reuse it anywhere else, never share it and never store it in plain text. Turn on two-factor authentication for the vault. Consider writing down recovery information and storing it securely offline, for example in a safe place at home.
Our overview of what a VPN does makes a related point: the tools that matter most for everyday security are the basics, and a password manager is among the most valuable.
Getting started without chaos
- and create a strong master passphrase.
- on the vault.
- from your browser if you wish.
- email, banking, work, cloud storage. Change them to unique generated passwords.
- through the rest, changing passwords as you log in.
- if you now use a separate manager, to avoid duplicates.
What a password manager does not do
- though autofill that refuses to fill on an unfamiliar domain can be a clue that a site is fake.
- If malware is on your computer, a vault that is unlocked can be exposed.
- in some designs.
- Any service can be targeted, which is why vault encryption and a strong master password matter.
We do not give incident-response advice. If you believe an account has been compromised, contact the service involved and follow its guidance.
Free versus paid
Free plans exist, often limited to one device type or fewer features. Paid plans add sync across all devices, sharing, advanced recovery and priority support. The sensible approach is to try the free tier of a reputable manager, see whether it fits and upgrade only if you need the extras. Be careful with unknown free managers, as with free VPNs, and check how the company makes money. Our guide to reading pricing and renewals applies to password managers as well: look at the renewal price and the refund policy.
Passkeys and the future
Many services now support passkeys, a way of signing in without a password, using a cryptographic key stored on your device and unlocked with a fingerprint, face or PIN. Password managers increasingly store passkeys too. They are designed to resist phishing. Adoption is still growing, and many sites still require passwords, so a password manager remains useful.
Questions to ask before you choose
- Who makes it, and how long has it been around?
- Is it audited by independent security reviewers?
- How is the vault encrypted, and can the company read it?
- What recovery options exist, and what are their risks?
- Does it support security keys or authenticator codes for the vault?
- Does it work on all my devices and browsers?
- Can I export my data easily?
- What does it cost over three years?
The short version
A password manager lets you use long, unique passwords everywhere without remembering them. Pick a reputable one, protect it with a strong master passphrase and two-factor authentication, move your most important accounts first and plan how you would recover access. It does not replace careful habits, but it is one of the most effective upgrades to everyday security you can make.
Frequently asked questions
What if I forget my master password?
Some designs offer no recovery by design. Others offer recovery methods with their own trade-offs. Record recovery information somewhere safe.
Is a browser’s built-in manager enough?
It can be a large improvement over reuse. Dedicated managers add features such as sharing, emergency access and cross-browser support.
Can the company read my vault?
In a zero-knowledge design it stores only encrypted data, but check independent audits rather than relying on a claim.

