Password manager guide: how it protects you and how to move to one

Password & accounts. Updated 2026-09-13. About 5 minutes to read.

Pick one password manager, protect it with a long passphrase and two-factor authentication, then change your email and banking passwords first.

Most account takeovers do not start with a clever hack. They start with a password that leaked from one site and still works on another. A password manager fixes that by giving every account a different password that you never have to remember.

This guide explains what a password manager actually protects, what happens if the company behind it is breached or you forget your master password, whether your browser's built-in manager is enough, and how to move your logins without locking yourself out.

How a password manager actually protects you

  • Unique passwords: when one site is breached, the stolen password opens nothing else. This defeats credential stuffing, where criminals replay leaked email and password pairs on other sites.
  • Phishing resistance: autofill only offers a password on the web address it was saved for. If it does not offer to fill, you may be on a fake site.
  • Encryption you control: good managers encrypt the vault on your device with a key derived from your master password, so the company cannot read your passwords.
  • Breach alerts: most managers flag saved passwords that appear in known breach data and passwords you reused.

What if the password manager company is breached?

It has happened. In 2022 attackers stole backup copies of customer vault data from LastPass. The passwords inside were encrypted, but website addresses in some vaults were not, and anyone with a weak master password was exposed to guessing attacks on the stolen copies.

The lesson is not to avoid password managers. It is to use a long master passphrase that cannot be guessed, turn on two-factor authentication for the vault, and change the passwords for your most important accounts if your provider ever reports a vault theft.

If you forget your master password

With a zero-knowledge manager, support cannot reset your master password, because they never had it. That is the price of the security. Set up a recovery route on day one, before you need it.

  • 1Password gives you an Emergency Kit containing your Secret Key. Print it and store it with your important papers.
  • Bitwarden offers emergency access, which lets a trusted person request access after a waiting period you choose.
  • Apple Passwords and Google Password Manager are tied to your Apple Account or Google Account, so their recovery follows those accounts.
  1. Write the master passphrase on paper and keep it with your passport or other important documents, not in a note on your phone.
  2. Print or save the recovery kit, recovery key or backup codes your manager offers, and store a copy away from your computer.
  3. Set up emergency access or a family organiser if your manager supports it, so one trusted person can help you back in.
  4. Test the recovery route once by signing in on a new browser with only the written details in front of you.

Browser built-in or a dedicated password manager?

The UK's National Cyber Security Centre says it is safe to let your browser or device save passwords on your own devices. Google Password Manager, Apple Passwords and the Microsoft Edge password manager all generate strong passwords and warn about breached ones. For many people that is enough, and it beats reusing passwords by a wide margin.

A dedicated manager earns its place when you use more than one ecosystem, such as an iPhone and a Windows laptop, when you need to share logins with family, or when you want emergency access and secure notes. Pick one and stick to it. Two managers saving different versions of the same password is how people get locked out.

Choosing one: realistic options

  • Bitwarden: open source, with a free plan covering unlimited passwords on unlimited devices. Premium rose to about 20 US dollars a year in January 2026.
  • 1Password: no free plan. The Individual plan was 3.99 US dollars a month billed annually after a March 2026 price rise.
  • Dashlane: no free plan since 16 September 2025. Premium was 4.99 US dollars a month billed annually at the time of writing.
  • KeePassXC: free, open source and offline. You handle syncing and backups yourself.
  • Built-in managers from Apple, Google and Microsoft: free, and a good choice if you live in one ecosystem.

Prices change often. Check the vendor's pricing page before you commit, and test the export feature so you know you can leave.

Migration: move your logins without breaking anything

  1. Install the manager on your main computer and phone, and create a master passphrase of five or six random words.
  2. Turn on two-factor authentication for the password manager account and save its recovery kit or codes offline.
  3. Export your saved passwords from your browser to a CSV file and import that file into the new manager.
  4. Delete the CSV file straight away and empty the recycle bin, because it holds every password in plain text.
  5. Turn off the browser's offer to save passwords, so there is only one place new passwords go.
  6. Open the manager's security report. Change your email password first, then banking, then every password it marks as reused or breached.
  7. Fix the long tail as you go: update each remaining password the next time you log in to that site.

An exported password file is the most sensitive file on your computer. Never email it, sync it or leave it in Downloads.

Frequently asked questions

Is it safe to keep all my passwords in one place?

Yes, when that place is encrypted and protected by a strong master passphrase and two-factor authentication. The alternative for most people is reused passwords, which are far more dangerous.

What master password should I use?

A passphrase of five or six random words chosen with dice or a generator, not a phrase from a song or book. It is long enough to resist guessing and easier to remember than a short string of symbols.

Should I store two-factor codes in my password manager?

It is convenient and far better than no two-factor authentication. For your email and the password manager itself, keep the second factor somewhere separate, such as an authenticator app on your phone or a security key.

Are free password managers safe?

The reputable ones are. Bitwarden's free plan and the managers built into Apple, Google and Microsoft products use strong encryption. Avoid unknown apps with no security record.

How do I share passwords with family safely?

Use a shared vault or sharing feature inside the manager, never text messages or email. Family plans from dedicated managers, and shared groups in Apple Passwords and Google Password Manager, let you share selected logins and revoke access later.

Tools that help

Related guides

Sources