Most people who get hacked are not victims of clever code. They reused a password, a site they barely remember was breached, and someone tried the same email and password everywhere else. A password manager fixes that problem by making a different, strong password for every account effortless. This guide explains what to look for, when the free option built into your phone or browser is enough, how passkeys change the picture, and how to move from one manager to another without losing anything along the way.
What a password manager actually does
The US Cybersecurity and Infrastructure Security Agency describes a password manager as "an easy-to-use program that generates, stores and even fills in all your passwords", and makes the key point plainly: "we only need to remember one strong password, the one for the password manager itself" (CISA). CISA's advice is that every account should have its own password of at least 16 characters, random or a passphrase of several unrelated words. Nobody can remember dozens of those. A manager can.
The standards bodies have moved the same way. NIST's digital identity guidelines, which shape how US government and many private services handle logins, say that services "SHALL allow the use of password managers and autofill functionality" and should let people paste passwords. They also say services should no longer force periodic password changes or arbitrary rules like "one symbol, one number", and should instead require length and check new passwords against lists of known breached ones (NIST SP 800-63B).
Is the free built-in option enough?
For many people, yes. Apple's Passwords app, Google Password Manager and the password managers built into Microsoft Edge and Firefox all generate, store, sync and fill passwords at no extra cost. The UK's National Cyber Security Centre calls browser password managers "the easiest way to remember your passwords, particularly if you use the same operating systems or browsers across your devices" (NCSC).
The NCSC also names the case where a separate app is worth having: standalone password managers "can synchronise passwords even when you have a mix of different browsers and devices". A household with a Windows laptop, an iPhone and an Android tablet is exactly that case. Built-in managers work best inside their own ecosystem and become awkward across them.
Signs a dedicated password manager is worth paying for:
- Mixed devices. You use Apple, Google and Microsoft products together, or more than one browser.
- Sharing. You want to share some logins with a partner, family members or a small team, with separate vaults and the ability to revoke access.
- Emergency access. You want a trusted person to be able to reach your accounts if something happens to you.
- More than passwords. You want to store secure notes, card details, document scans or two-factor codes in one place.
- Breach alerts and health reports. You want to be told which saved passwords are weak, reused or found in a breach. Some free built-in managers do this too, so check before paying.
- Business use. You need admin controls, staff onboarding and offboarding, and an audit trail.
If none of those apply, the free manager already on your devices, used properly, is a large improvement over reusing passwords. The best password manager is the one you actually use for every account.
What to check before you choose
Security model
Look for end-to-end encryption, sometimes described as "zero knowledge": your vault is encrypted on your device with a key derived from your master password, so the company cannot read it. Check whether the vendor has published independent security audits, and how it has handled past incidents. A company's response to a breach, how quickly it disclosed it and how clearly it explained what users should do, tells you a lot.
Account protection
The NCSC strongly recommends turning on two-step verification for the password manager itself, because "even if a cyber criminal knows the primary password, they still won't be able to access your account" (NCSC). Make sure the product supports an authenticator app or a hardware security key, not only text messages.
Recovery
Because the company cannot read your vault, it usually cannot reset your master password for you. The NCSC notes that "it's really important to remember your primary password" and that many managers offer recovery options such as hints or emergency access through trusted contacts. Find out what the recovery route is before you need it.
Passkey support
Check that the manager can create, store and sign in with passkeys on every platform you use. This is where products differ most at the moment, and it matters for the next decade.
Import and export
Make sure you can get your data in easily and, just as important, get it out again. A product that makes leaving hard is a product you are locked into.
Price after the first year
Compare the renewal price, not only the introductory one, and check what the free tier allows.
Passkeys: what they are and how they fit
A passkey is, in the FIDO Alliance's words, "an authentication credential based on FIDO standards, that can be stored on your phone or computer, or in a hardware security key". Instead of typing a password, you approve the sign-in "with the same process that they use to unlock their device (biometrics, PIN, or pattern)" (FIDO Alliance). The site never receives a secret it could leak, and a passkey only works on the real site it was made for, which is why FIDO calls passkeys "phishing-resistant and secure by design".
Passkeys come in two kinds. Synced passkeys are copied between your devices through a cloud service, which is what Apple, Google and most password managers do. Device-bound passkeys never leave one device, such as a hardware security key. Synced passkeys are more convenient; device-bound ones suit people who want the strictest control.
Passkeys do not make a password manager unnecessary. They make the choice of manager more important, because that is where your passkeys live. A few practical points:
- Passwords and passkeys coexist. Google, for example, lets you keep your password and choose whether to skip it when a passkey is available, and lets you remove a passkey from a lost device by signing in elsewhere (Google Account Help).
- Your biometrics stay on your device. Google states that fingerprint or face data used to unlock a passkey "stays on your device and is never shared with Google".
- Start with the accounts that matter most: your main email account, then banking, then shopping and social accounts. Email comes first because it is how every other password gets reset.
- Keep a fallback. Until every service supports passkeys everywhere, you will still need a manager for passwords, and a way back in if you lose a device.
How to switch password managers safely
Switching is easier than most people expect, but the export file is the most dangerous object in the whole process. Apple's own support page is blunt: "Passwords you export are not encrypted and are visible to anyone who has access to the file" (Apple Support).
- Set up the new manager first. Create the account, choose a long, unique master password or passphrase, turn on two-step verification and note the recovery details.
- Check what the old manager can export. Most export a CSV file of usernames and passwords. Some items may not come across: Apple, for instance, says you cannot export Wi-Fi passwords or Sign in with Apple accounts. Passkeys usually cannot be moved through a CSV file at all.
- Export on a computer you trust, not a shared or work machine. Save the file locally, not to a synced cloud folder or an email.
- Import into the new manager. Most accept files from the major competitors directly. Bitwarden's documentation, for example, lists imports from LastPass, 1Password, Chrome, Firefox, Safari and KeePass, and warns that "importing does not check for duplicates", so import once (Bitwarden Help Center).
- Delete the export file immediately, and empty the recycle bin or trash. Bitwarden's advice is to "delete the exported data file from your computer", so that a later compromise of the computer does not expose every password at once.
- Move the things a file cannot carry. File attachments usually need to be uploaded again by hand. For passkeys, the simplest route is to sign in to each service and create a new passkey in the new manager, then remove the old one in that account's security settings.
- Test before you close the old account. Use the new manager for a week or two. Sign in to your email, bank and a handful of everyday sites with it.
- Turn off the old manager's autofill and the browser's own password saving, so two managers do not compete to fill the same form.
- Then delete the old vault and cancel any subscription, so an old copy of your passwords is not left sitting behind a password you may stop remembering.
The FIDO Alliance has published credential exchange specifications that define "a standard format for transferring all types of credentials in a credential manager including passwords, passkeys and more in a manner that is secure by default" (FIDO Alliance). As managers adopt them, direct and encrypted transfers should replace the plain CSV file. Until your old and new manager both support that route, follow the steps above.
After you switch: the first hour
- Run the manager's password health check, if it has one, and change any password it flags as reused or breached, starting with email.
- Add passkeys to your most important accounts.
- Write your master password down once and keep it somewhere physically safe at home, away from the computer. On a shared or public device, the NCSC says you "should never save your password in the browser".
- Set up emergency access or a recovery kit, if the manager offers one.
Whichever product you choose, the gains come from the habit: a unique password or a passkey for every account, a strong master password, and two-step verification on the manager itself.