What a Password Manager Does

A password manager stores login credentials in an encrypted vault, protected by a single master password (and ideally multi-factor authentication). Instead of remembering dozens of individual passwords, a person only needs to remember one strong master password; the manager fills in the rest automatically on recognized sites and apps.

Why Reusing Passwords Is Risky

When the same password is used across multiple sites, a data breach at just one of those services can expose accounts everywhere else the password was reused — a technique called credential stuffing. Because breaches happen regularly and are often outside any individual's control, using a unique password for every account limits the damage a single breach can cause.

How Password Generation Helps

Most password managers include a generator that creates long, random passwords that are far harder to guess or crack than anything a person would typically choose and remember on their own. Because the manager stores and fills these passwords automatically, there's no need to actually memorize them.

Built-In Browser and OS Password Managers

Chrome, Edge, Firefox, Safari, and Windows all include some form of built-in password saving and generation. These provide a real security improvement over reused, memorized passwords, and are a reasonable starting point. Standalone password manager applications often add features like more robust cross-platform syncing, secure notes, and monitoring for passwords exposed in known breaches.

Limitations Worth Understanding

  • Single point of failure: if the master password is compromised or forgotten and no recovery method exists, access to the whole vault can be lost or exposed.
  • Autofill risks: autofill can occasionally populate fields on a convincingly disguised phishing page if the domain matching isn't precise, though most modern managers guard against this.
  • Device dependency: if a password manager isn't synced or backed up properly, losing the device it's installed on can complicate access.
  • Trust in the provider: using a third-party password manager means trusting that provider's own security practices, since a breach of the manager itself would be significant.

Choosing and Setting Up a Password Manager

  • Choose a long, unique master password — ideally a memorable passphrase of several unrelated words rather than a short complex string.
  • Turn on multi-factor authentication for the password manager account itself.
  • Use the built-in breach-monitoring feature, if available, to get alerted when a stored password appears in a known data breach.
  • Store a secure backup of the master password or recovery codes somewhere offline, such as a written copy kept in a safe location.