The average person now has well over a hundred accounts. Choosing a strong, unique password for each is impossible from memory, and reusing one password everywhere means a single breached site unlocks everything else.
That second sentence describes how most account takeovers actually happen. Attackers do not crack your password — they take credentials leaked from one breach and replay them automatically across thousands of services until something matches. The technique is called credential stuffing, it is fully automated, and it works precisely because people reuse passwords.
A password manager solves this by making the impossible thing easy: a different, long, random password for every account, remembered by the software rather than by you.
What it actually does
- Generates high-entropy passwords — typically 16–32 characters of mixed types
- Stores them encrypted in a vault
- Autofills them on the correct site only
- Also stores cards, IDs, secure notes, identities and often two-factor authentication codes
You remember one credential: the master password. Every other password becomes disposable and unique.
The four types
| Type | Examples | Trade-off |
|---|---|---|
| Browser built-in | Chrome, Edge, Safari, Firefox | Free and effortless within one browser; weaker across platforms and browsers |
| Cross-platform cloud | Bitwarden, 1Password, Dashlane, NordPass | Syncs everywhere, rich features; depends on the provider’s security |
| Local / offline | KeePass, KeePassXC | Nothing leaves your device — most secure, least convenient; sync is manual |
| Enterprise / SSO | Workplace password managers | Managed by your organisation, often with policy enforcement |
How the security works
The concept that matters is zero-knowledge architecture: your master password never leaves your device. It is used locally to derive an encryption key, which encrypts the vault before anything is transmitted. The provider stores only ciphertext.
The key derivation step
Because a master password has limited entropy, it cannot be used directly as a key — that would make guessing cheap. Instead it passes through a key derivation function that is deliberately expensive and slow:
- PBKDF2 — iterated hashing; strong implementations use very high iteration counts
- Argon2id — memory-hard, designed to resist dedicated hardware attacks; generally considered the better choice where available
- bcrypt — widely used and well-studied
The vault cipher
Vaults are typically encrypted with AES-256 or XChaCha20. The algorithms are standard and public; security comes from the implementation and from the strength of your master password, not from the algorithm being secret.
Two variants of sync, and the difference is significant:
- End-to-end encrypted sync — data is encrypted before it leaves the device and decrypted only on your devices. The provider cannot read it
- Server-side decryption — the provider holds the ability to decrypt. Materially weaker, even if the individual storage layers are well protected
The master password is the whole game
With zero-knowledge design, the provider cannot recover your vault, cannot reset it, and cannot read it. That is a genuine security property. It also means the master password is the single point of failure — if it is weak, everything else is decorative.
- Length beats complexity. Four or five unrelated random words dramatically outperform an eight-character password with symbols, and are far easier to type correctly
- Never reuse it anywhere else. A master password used on a website is a master password an attacker may already have
- Protect the vault with two factors — enable 2FA on the password manager itself, using an authenticator app or hardware key rather than SMS where possible
- Do not store the master password inside your own vault — it creates a circular dependency on a device you may be unable to open
What happens when a provider is breached
The 2022 LastPass breach is the clearest available case study: customer vaults were stolen, and — importantly — in some cases were stored with insufficiently protected backups. Stolen encrypted vaults with a strong master password remain extremely difficult to open. Stolen vaults with a weak or reused master password did not.
The lesson is not “password managers are unsafe”. The lesson is that under zero-knowledge design, your master password strength is the security boundary — the provider’s breach status matters, but your password matters more. This is why a long, unique, never-reused master password is not optional advice.
Autofill — where the real risk sits
Autofill is the feature people use most and scrutinise least. Two distinct concerns:
Phishing resistance
A well-built manager matches credentials to the actual registered domain. If you visit paypal.com.attacker-example.net, a correctly configured manager will not fill your PayPal credentials, because the registrable domain does not match. This is a genuine defence that a human typing a password does not have — you cannot reliably eyeball a lookalike domain under time pressure, and neither can most people.
Check that your manager uses strict domain matching rather than loose substring matching. If it will autofill on a subdomain of an unrelated parent, that is a configuration to tighten.
Script-based extraction
A malicious page could theoretically trigger autofill repeatedly to harvest stored values for a domain. Modern managers mitigate this by filling only on explicit user action and by limiting what is offered. Prefer managers that fill on click rather than automatically on page load.
Where should two-factor codes live?
Most modern managers can also store TOTP codes. The trade-off is real: it is far more convenient, but if an attacker obtains both your vault and your master password, they hold the password and the second factor together.
A reasonable split: use the manager’s built-in 2FA for low-value accounts, and a separate authenticator app or hardware key for anything high-value — your email, your bank, and the password manager itself. The recovery pivot matters most: your primary email account typically resets everything else, so it deserves an independent second factor.
Passkeys, and where this is heading
Passkeys replace passwords entirely with a cryptographic key pair — the private key stays on your device or in your vault, and the site only ever stores the public half. There is nothing to type, nothing to phish, and nothing to reuse.
Major password managers now store and sync passkeys, as do platform providers like Apple and Google. They are phishing-resistant by construction because the credential is bound to the origin — a convincing fake site cannot complete the exchange.
Adoption is real but incomplete. For now the sensible position is a strong manager handling both your remaining passwords and your growing set of passkeys.
Getting started safely
- Choose for your actual platforms — a Windows-only solution is useless if you also use a phone
- Set the master passphrase — long, random, unique, written down offline as a recovery kit
- Enable 2FA on the vault itself before importing anything
- Import existing passwords from your browser’s store. Export only when needed and delete the export file immediately afterwards — an unencrypted CSV sitting in your downloads folder is the worst security outcome this process can produce
- Secure your primary email first. It is the recovery mechanism for every other account; losing it means losing the ability to reset anything
- Prioritise the top ten — email, banking, phone carrier, cloud storage, social accounts
- Generate unique credentials for each as you touch them
- Fix reused passwords gradually. Do not attempt all hundred in a weekend; that is how people abandon the process
- Save the emergency kit offline — printed or on encrypted storage, not in the cloud account it is meant to recover you from
Objections, examined
“It’s just one big honeypot.”
It is one encrypted target rather than a hundred plaintext ones. The alternative — reuse — has already been demonstrated to fail at scale. And under zero-knowledge design, the honeypot is unreadable without your master password.
“I’ll just write them down.”
Surprisingly, a physical list kept at home is not unreasonable — it is protected from the remote attacks that dominate real risk, though not from visitors or fire. The unqualified version is what fails: a list in a notes app, an email to yourself, or a spreadsheet in cloud storage converts a physical risk into a networked one.
“A spreadsheet works fine.”
A spreadsheet is typically unencrypted, unsynced securely, unautofilled, ungenerated, and offers no phishing defence. It is a list, not a password manager. Use it only as a deliberate offline backup, encrypted and stored properly.
“I can remember all mine.”
Consistently, no — and the evidence is in how many people reuse. If you genuinely have unique, long credentials for every account, you are already doing what the tool automates.
Frequently asked questions
What if I forget the master password?
With a true zero-knowledge provider, you cannot recover it — that is the property working as designed. What you can do is plan for it: save the recovery kit offline at the outset, set up the provider’s emergency access or account recovery feature where offered, and keep at least one trusted person able to reach your recovery information. Discovering you are locked out is entirely avoidable if you set it up before it matters.
Are browser built-in managers good enough?
They are substantially better than reuse and better than most people’s alternatives, and they are free. Their weaknesses are cross-browser portability, fewer features, sync tied to one ecosystem, and less control over autofill behaviour. For someone currently reusing passwords, switching to the built-in manager tonight is a clear improvement. For someone handling a large number of accounts across platforms, a dedicated manager earns its cost.
Is it safe to store card numbers and documents?
Card details and notes are the standard use case and are fine in a properly encrypted vault. What I would not store is anything that acts as a master recovery factor for the vault itself — and I would keep genuinely sensitive documents in a dedicated secure store rather than treating the password manager as a general filing cabinet.
Do I still need antivirus and 2FA?
Yes to both. A password manager defends against credential reuse and phishing; it does nothing about malware, keyloggers or device compromise. Multi-factor authentication remains one of the single most effective defences available, and it should be on the vault itself as well as your important accounts. These are layers, and the point of layers is that no one of them has to be perfect.
Which one should I choose?
There is no universally correct answer, and brand recommendations date quickly. Evaluate on: whether it supports all your platforms, whether sync is end-to-end encrypted, whether it is independently audited and runs a bug bounty, whether it supports passkeys and hardware keys, and whether the master password is protected with Argon2id. Open-source options have the additional advantage that their claims can be inspected rather than taken on trust.
This article explains general technology concepts. For the wider defensive picture see our cybersecurity guide, and for recognising the attacks a password manager defends against, phishing types.















