Do You Need a Password Manager, and How to Choose One
If you’ve ever typed “forgot password” into a login screen for the third time in a week, you’re not alone. Most of us are juggling accounts for email, banking, shopping, streaming, work systems and social media, and the honest truth is that nobody can reliably remember dozens of long, unique, random passwords. So we cut corners. We reuse the same one everywhere, or a slight variation of it, or we pick something memorable that’s also easy to guess. A password manager exists to solve exactly this problem, and it’s one of the few pieces of “security software” that genuinely makes your life easier rather than harder.
A password manager is a tool that creates, stores and automatically fills in strong, unique passwords for every account you use. Instead of remembering fifty passwords, you remember one, or use your fingerprint or face to unlock a vault that holds the rest. It sounds simple, and it is, but the details of how these tools work, and which type suits you, matter more than most people realise.
In this guide, you’ll learn what a password manager actually does, whether you genuinely need one, the main types available, and what to weigh up when choosing between them. This is general guidance rather than a recommendation of any specific product, so it’s worth comparing a shortlist against your own needs before you commit to one.
- Reusing the same password across multiple sites is one of the most common ways accounts get compromised, and a password manager removes the need to do it.
- A password manager lets you use a long, unique, hard-to-guess password on every account without having to remember each one yourself.
- Options range from browser built-in managers to dedicated cross-platform apps and offline-only vaults, each with different trade-offs around convenience and control.
- Most managers can flag reused, weak or previously breached passwords, giving you a practical to-do list for tightening up your accounts.
- Two-factor authentication and being alert to phishing attempts both work alongside a password manager rather than replacing it.
- The “best” password manager is really the one that fits how you actually use your devices day to day, not necessarily the one with the longest feature list.
What does a password manager actually do?
At its core, a password manager stores your login details in an encrypted vault and can generate long, random passwords for you on the spot. Rather than typing something you’ll need to reuse or remember, you let the manager suggest something like a 20-character string of letters, numbers and symbols that would take a computer an impractically long time to guess or crack. You never need to memorise it, because the manager remembers it for you.
Instead of remembering dozens of passwords, you remember one strong “master” password, or use biometrics such as a fingerprint or face scan, to unlock the vault. That single point of access is protected by encryption, meaning that even if someone got hold of the underlying data file, they shouldn’t be able to read it without your master password or key.
Most managers can then automatically fill your username and password into a website or app, saving you the temptation to reuse something you already know just because it’s quicker. This autofill function is arguably the single biggest reason people stick with a password manager once they start using one. It removes friction, and friction is usually what pushes people back towards weak, memorable passwords.
Many password managers also include a browser extension, so the whole process happens without you needing to copy and paste anything manually. Some go further and offer a desktop app, a mobile app, and integration with your phone’s own biometric unlock, so the same saved login works whether you’re on a laptop, tablet or phone.
Beyond passwords, many tools also let you store other sensitive information in the same encrypted vault. This might include secure notes, software licence keys, banking details for faster checkout, or even scanned copies of important documents. It becomes a single, protected place for anything you’d rather not leave lying around in an email inbox or a notes app.
Do you actually need a password manager?
If you reuse passwords across more than one account, or struggle to remember several different ones, a password manager solves a genuine and common problem. It’s worth being honest with yourself here. Most people, even those who consider themselves careful, have at least a handful of accounts sharing the same password or a close variant of it.
Password reuse is risky because if one website you use suffers a data breach, attackers will typically try the same email-and-password combination on other popular sites. This kind of attack, often called “credential stuffing”, doesn’t require guessing your password at all; it simply reuses one that has already leaked elsewhere, often from a breach you were never even told about, or one you’ve long forgotten. Automated tools can attempt millions of these combinations very quickly across thousands of websites, which is why a breach on a site you barely use can still end up compromising your email or banking account months later.
There’s also the simpler, everyday risk of weak passwords. Anything based on a pet’s name, a birthday, or a common word with a number tacked on the end is far easier to guess than most people assume, particularly once you factor in how much personal information is often publicly available on social media.
If every one of your accounts already has a long, unique password that you’re confidently managing another way, perhaps written down securely and updated diligently, you may get less added benefit from a manager. But that’s genuinely rare. For most people, a password manager removes a real and persistent weak point in their digital life, and it tends to do so with less ongoing effort than any manual system.
It’s also worth thinking about who else in your household might benefit. Family members who share streaming logins, or elderly relatives who reuse the same password everywhere out of necessity rather than choice, are often the people most exposed to credential stuffing and phishing, and a well-chosen manager can quietly protect them too.
What types of password manager are available?
There are three broad categories, and they differ mainly in where your passwords are stored and how they sync across your devices. Understanding the distinction matters more than comparing individual brand names, because it shapes how the tool will actually fit into your routine.
Browser built-in managers come free with browsers such as Chrome, Safari and Edge, and sync passwords to your account on that browser. If you’re already signed into your browser account and use the same browser on your phone and computer, this is the lowest-effort option, since there’s nothing extra to install or set up.
Dedicated cloud-synced apps work across multiple browsers and operating systems, and usually add extra features like breach alerts, secure sharing with family members, and support for storing things beyond passwords, such as documents or payment cards. These tend to be the most flexible choice if you regularly switch between browsers or use a mix of Windows, Mac, Android and iOS devices.
Offline or local-only vaults store your data on your own device rather than syncing it to a company’s servers, which some people prefer for extra control, at the cost of convenience across devices. These suit people who are particularly wary of cloud storage in general, or who only really need password management on one machine, though you’ll need to manage your own backups carefully since there’s no company keeping a spare copy for you.
There’s a fourth option worth mentioning briefly: some people still use a simple, well-organised spreadsheet or a notebook kept somewhere secure. This isn’t a password manager in the technical sense and doesn’t offer encryption, autofill, or breach checking, but for a very small number of accounts it’s better than reusing the same weak password everywhere. It’s not something we’d generally recommend once you have more than a handful of logins to juggle, though.
Browser built-in vs dedicated app vs offline vault
Each option suits a slightly different type of user, so it’s worth matching the choice to how you actually use your devices, rather than assuming one is objectively “best” for everyone.
| Type | Works across browsers/devices | Best suited to |
|---|---|---|
| Browser built-in | Usually limited to that one browser | People who use a single browser everywhere and want a free, no-setup option |
| Dedicated cloud-synced app | Yes, across most browsers and operating systems | People who switch devices or browsers regularly and want extra features |
| Offline/local-only vault | No, stays on the device unless you sync it manually | People who prioritise control over convenience and mainly use one device |
Browser built-in managers have improved considerably in recent years, and for many people they’re genuinely good enough, particularly if you’ve already committed to one browser ecosystem across your phone and computer. The main limitation shows up if you ever need to switch browsers, share a login securely with a family member, or want features like breach monitoring baked in.
Dedicated apps tend to be the more capable option overall, largely because that’s their entire purpose rather than a secondary feature bolted onto a browser. The trade-off is usually a bit more setup, and in some cases an ongoing subscription for the fuller feature set, though free tiers with solid core functionality are common.
Offline vaults appeal to a smaller, more security-conscious audience. They avoid handing your encrypted data to a third party’s servers at all, which some people find reassuring, but you take on more responsibility for backing the vault up yourself and for getting your data onto a new device if your current one is lost, stolen or replaced.
What to look for when choosing one
Once you’ve settled on a broad type, a handful of practical features are worth checking before you commit.
- Cross-platform support: check it works properly on every device and browser you actually use, not just the main one.
- Autofill reliability: a manager that constantly fails to fill in login forms correctly will quickly become an annoyance you work around rather than a habit you trust.
- Breach and reuse alerts: the ability to flag passwords that are weak, reused, or have appeared in a known data breach is genuinely useful and turns the manager into an ongoing check-up rather than a one-off setup.
- Secure sharing: if you share logins with family or colleagues, look for a proper sharing feature rather than sending passwords over text or email.
- Two-factor authentication support: the manager itself should support unlocking with a second factor, and ideally can also store or generate the codes needed for two-factor authentication on other sites.
- Recovery options: understand exactly what happens if you forget your master password or lose your device, since some systems have no way to recover a forgotten master password by design, for security reasons.
It’s worth spending a little time reading how each option handles the technical side of encryption and account recovery, since this is where the real differences between providers tend to show up, even if the day-to-day experience feels similar on the surface.
Password managers, phishing and two-factor authentication
A password manager is a strong foundation, but it isn’t a complete security strategy on its own, and it’s worth understanding what it doesn’t protect against. It won’t stop you from being tricked into typing your master password into a convincing fake login page, for instance, which is why knowing how to spot and avoid phishing scams remains just as important even once you’re using a manager for everything else.
One quietly useful side effect of using a password manager is that its autofill feature only offers to fill in details on the genuine website it has saved, not a lookalike copycat site. If you visit a fake banking site and your manager doesn’t offer to autofill your login as normal, that’s a useful signal something is wrong, on top of any other warning signs.
Two-factor authentication, sometimes called multi-factor authentication, adds a second check beyond your password, usually a one-time code sent to your phone or generated by an app. Turning this on for your most important accounts, particularly email and banking, means that even if a password were somehow exposed, an attacker would still need that second code to get in. Many password managers can store or generate these codes themselves, which keeps everything in one place without meaningfully reducing the security benefit.
It’s also worth remembering that the device you’re doing all this on needs to be looked after too. A password manager stored on a laptop riddled with malware, or one running so slowly that you’re tempted to skip updates, isn’t as protected as it should be. If your machine has been sluggish for a while, it’s worth working through some proper fixes for a slow laptop before you assume everything on it, including your password vault, is running as securely as it should.
Setting one up without the overwhelm
The idea of updating dozens of passwords in one go is enough to put most people off starting at all, so it helps to approach it gradually rather than all at once. Begin with the accounts that matter most: your primary email address, since it’s often the recovery route into everything else, followed by online banking, and any account tied to payments or personal data.
From there, most managers will highlight your weakest or most reused passwords automatically, giving you a practical, prioritised list rather than leaving you to guess where to start. Working through a handful each week is far more sustainable than trying to fix everything in one sitting, and it still gets you to a much stronger position within a month or so.
New accounts are the easy part, since the manager will simply generate a strong password the first time you sign up for something and remember it from that point on. It’s the years of existing accounts that take a bit of patience to work through, but the improvement in your overall security is genuinely significant once you have.
If you’re setting this up on a new device, or across a home network with several devices connecting to shared Wi-Fi, it’s worth also checking your router and network security are up to scratch. Anyone curious
Sam Allcock is the founder and editor of Morrow Tech. He has spent over a decade in digital publishing and writes about the technology worth your attention, from AI to everyday gadgets.
