Using a different strong password for every account is one of the most useful ways to reduce the damage caused by a stolen password.
The difficulty is remembering all of those passwords.
A password manager solves much of that problem by creating, storing and retrieving passwords for you.
This means you can use long and unique passwords without trying to memorize every one.
What is a password manager?
A password manager is software that stores login information in a protected vault.
Depending on the product, it may also:
- generate random passwords
- fill usernames and passwords into login forms
- sync passwords between trusted devices
- alert you when a stored password may have appeared in a known data breach
- store secure notes or other account information
- manage passkeys where supported
The main idea is simple.
Instead of memorizing dozens of passwords, you strongly protect the password manager and allow it to remember the individual account passwords.
Why are password managers useful?
People often reuse passwords because remembering many long passwords is difficult.
Password reuse creates an important security problem.
If one website exposes a reused password, criminals can try the same email address and password on other services.
A password manager makes it practical to give every account a different password.
For example:
Email account: one unique password
Shopping account: another unique password
Cloud storage: another unique password
Social account: another unique password
You do not need to know those generated passwords from memory.
The password manager can generate passwords for you
Modern password managers usually include a password generator.
It can create a long random password such as a combination of letters, numbers and symbols.
Because you do not need to memorize that password, it can be much more random than a password you would normally create yourself.
This helps avoid predictable patterns such as names, birthdays, favourite teams or simple substitutions.
One account, one generated password
A useful habit is:
Use a different generated password for every account.
If one password is exposed, the other passwords remain different.
This limits how far one compromised credential can spread.
What is the vault?
The vault is the protected collection in which the password manager stores your login information.
A reputable password manager should protect stored information using strong security mechanisms such as encryption.
The details vary between products, which is why choosing a reputable and actively maintained password manager matters.
The vault becomes an important account
A password manager improves security, but it also concentrates valuable information in one place.
That makes the vault especially important to protect.
If someone gains access to an unlocked vault, they may gain access to many stored accounts.
Think of the password manager as one of your most important digital accounts.
Protect the main password carefully
Many password managers use a main password or passphrase to unlock the vault.
This password should be:
- long
- unique
- difficult for another person to predict
- used only for the password manager
Do not reuse your email password, computer password or another account password as the main password for your vault.
A passphrase can work well for the main password
The main password is one of the few passwords you may genuinely need to remember.
A long passphrase made from unrelated words can be easier to remember than a long random string.
For example, imagine a structure such as:
lantern coral meadow orbit velvet
That is only an illustration.
Do not use that exact phrase.
Your own main passphrase should be unique and not based on personal information or a familiar quotation.
Turn on multi factor authentication for the password manager
If your password manager supports multi factor authentication, enable it.
This adds another verification step when someone attempts to access the vault.
It means that knowing the main password alone may not be enough to enter the account.
Protect the recovery methods for this additional factor carefully as well.
Understand recovery before you depend on the manager
Password managers handle account recovery in different ways.
Some may provide recovery codes, trusted devices, emergency recovery options or other procedures.
Others may make recovery deliberately difficult because the provider cannot simply reveal your encrypted vault contents.
Before moving all of your accounts into a password manager, learn what happens if:
- you forget the main password
- you lose your phone
- you replace your computer
- you lose access to your multi factor method
- the password manager account becomes locked
Follow the provider's official recovery instructions and keep any recovery information in a safe location.
Do not store the main password inside the same locked vault
You need a way to unlock the vault before you can read information stored inside it.
That means relying only on a copy of the main password stored inside the same vault does not solve the recovery problem.
If you keep a recovery copy, protect it separately according to the password manager provider's instructions.
Choose a reputable password manager
Do not select a password manager only because an advertisement says it is secure.
Look at the product and the organization behind it.
Useful questions include:
- Does the provider have a good security reputation?
- Does the software receive regular updates?
- Does it protect stored information using encryption?
- Does it support multi factor authentication?
- Does it work on the devices you actually use?
- Can it sync safely between those devices if you need syncing?
- Does it provide alerts for known exposed passwords?
- Does it explain account recovery clearly?
- Does it provide a clear privacy policy?
Built in and separate password managers
Password management features can appear in browsers, operating systems and separate password manager applications.
Do not assume that one category is automatically secure or insecure.
What matters is the security design, reputation, update history, authentication options and whether the product fits the devices and accounts you use.
Cloud storage and local storage have different tradeoffs
Some password managers synchronize an encrypted vault through an online service.
This can make the same passwords available on several devices.
Other designs keep the main password database under more direct local control.
Each approach has advantages and responsibilities.
For example, synchronization can improve convenience, while a locally managed vault may require you to handle backups and device transfers yourself.
Do not choose only from the words cloud or local.
Evaluate the complete security and recovery design.
Use the manager only on devices you trust
A secure vault cannot fully protect you if the device using it is already controlled by another person or by malicious software.
Protect your computer and phone with:
- a device lock
- current software updates
- automatic locking after inactivity
- careful control of who can use the device
Avoid unlocking your password vault on public or untrusted computers.
What does automatic filling do?
Many password managers can fill a saved username and password into a login page.
This saves time and reduces the need to copy or type long generated passwords.
Use this feature only on trusted devices and check that you are visiting the intended website or application.
A password manager is useful, but it does not make every login page trustworthy.
A password manager does not make phishing impossible
Passwords themselves can still be targeted by phishing.
A convincing fake website may try to persuade you to reveal credentials, approve a login request or provide recovery information.
Do not treat the presence of a password manager as permission to ignore the website address or security warnings.
Continue to check where you are signing in.
Start with your most important accounts
You do not need to move every password into the manager in one day.
Start with accounts that could cause serious problems if taken over.
Examples may include:
- your main email account
- financial accounts
- cloud storage
- important work accounts
- shopping accounts containing payment information
- social accounts
Your email account deserves special attention because many services use email for password resets.
Replace reused passwords first
If you discover that several accounts use the same password, those accounts should be a priority.
For each account:
- open the real account website or application
- sign in normally
- open its password or security settings
- use the password manager to generate a new unique password
- save the new password in the vault
- confirm that you can sign in with it
- enable multi factor authentication if the service supports it
Repeat the process gradually for the rest of your accounts.
Do not change every password just because time has passed
A password manager makes password changes easier, but that does not mean every password needs to be replaced on a fixed schedule.
Current password guidance focuses more on changing passwords when there is a reason.
Examples include:
- the password was exposed in a breach
- you reused it on another service
- someone else knows it
- the account shows suspicious activity
- the service requires a change because of a security incident
When you replace a password, create a genuinely new unique password.
What about passkeys?
Passkeys are a newer authentication method supported by a growing number of services.
They can reduce reliance on traditional passwords.
Some password managers can also store or synchronize passkeys.
You do not need to choose between learning about password managers and learning about passkeys.
During the transition to newer authentication methods, many people will use both.
A password manager is not a complete security system
A password manager solves an important problem, but it does not replace other protections.
You should still:
- turn on multi factor authentication
- keep devices and software updated
- recognize phishing attempts
- protect account recovery methods
- review alerts about suspicious account activity
- use passkeys when an appropriate trusted service supports them
Common password manager mistakes
- reusing the vault's main password somewhere else
- using a weak or predictable main password
- leaving the vault unlocked on a shared device
- ignoring multi factor authentication
- choosing an unknown product without checking its reputation
- failing to understand recovery before relying on the vault
- keeping old reused passwords after installing the manager
- assuming the manager makes phishing impossible
A practical password manager checklist
Before relying on a password manager, check:
- Is the provider reputable?
- Is the product actively updated?
- Does it protect stored information with encryption?
- Can I turn on multi factor authentication?
- Is my main password long and unique?
- Do I understand the recovery process?
- Does it work on my trusted devices?
- Can it generate a different password for every account?
- Have I started replacing reused passwords?
The main idea
A password manager makes strong password habits practical.
It can generate and store long unique passwords so you do not need to memorize a different complicated password for every account.
The tradeoff is that the password manager itself becomes extremely important.
Choose a reputable product, protect the vault with a strong unique main passphrase, turn on multi factor authentication and understand recovery before depending on it.
Used carefully, a password manager can greatly reduce the need to reuse passwords across accounts.
Continue learning
Review How Strong Passwords and Passphrases Work if you want to review password length, uniqueness and passphrases.
The next Digital Safety lesson will show how to set up and organize a password manager in a careful step by step process.