Password & accounts. Updated 2026-09-13. About 5 minutes to read.
Pick one password manager, protect it with a long passphrase and two-factor authentication, then change your email and banking passwords first.
Most account takeovers do not start with a clever hack. They start with a password that leaked from one site and still works on another. A password manager fixes that by giving every account a different password that you never have to remember.
This guide explains what a password manager actually protects, what happens if the company behind it is breached or you forget your master password, whether your browser's built-in manager is enough, and how to move your logins without locking yourself out.
It has happened. In 2022 attackers stole backup copies of customer vault data from LastPass. The passwords inside were encrypted, but website addresses in some vaults were not, and anyone with a weak master password was exposed to guessing attacks on the stolen copies.
The lesson is not to avoid password managers. It is to use a long master passphrase that cannot be guessed, turn on two-factor authentication for the vault, and change the passwords for your most important accounts if your provider ever reports a vault theft.
With a zero-knowledge manager, support cannot reset your master password, because they never had it. That is the price of the security. Set up a recovery route on day one, before you need it.
The UK's National Cyber Security Centre says it is safe to let your browser or device save passwords on your own devices. Google Password Manager, Apple Passwords and the Microsoft Edge password manager all generate strong passwords and warn about breached ones. For many people that is enough, and it beats reusing passwords by a wide margin.
A dedicated manager earns its place when you use more than one ecosystem, such as an iPhone and a Windows laptop, when you need to share logins with family, or when you want emergency access and secure notes. Pick one and stick to it. Two managers saving different versions of the same password is how people get locked out.
Prices change often. Check the vendor's pricing page before you commit, and test the export feature so you know you can leave.
An exported password file is the most sensitive file on your computer. Never email it, sync it or leave it in Downloads.
Yes, when that place is encrypted and protected by a strong master passphrase and two-factor authentication. The alternative for most people is reused passwords, which are far more dangerous.
A passphrase of five or six random words chosen with dice or a generator, not a phrase from a song or book. It is long enough to resist guessing and easier to remember than a short string of symbols.
It is convenient and far better than no two-factor authentication. For your email and the password manager itself, keep the second factor somewhere separate, such as an authenticator app on your phone or a security key.
The reputable ones are. Bitwarden's free plan and the managers built into Apple, Google and Microsoft products use strong encryption. Avoid unknown apps with no security record.
Use a shared vault or sharing feature inside the manager, never text messages or email. Family plans from dedicated managers, and shared groups in Apple Passwords and Google Password Manager, let you share selected logins and revoke access later.