Password Managers, Explained Without the Sales Pitch

What a password manager actually does, why your browser is a partial solution, and the honest answer to the question everyone asks first.

Illustration of a password manager vault
Illustration of a password manager vault

Most password manager advice is written by companies selling password managers. Here is the version without that.

The problem they solve is reuse, not complexity

The common assumption is that password managers exist to help you create complicated passwords. That is a side benefit. The actual problem is reuse.

Almost nobody gets their password guessed or cracked. What happens instead is that some site you registered with years ago gets breached, and the attacker takes that email and password pair and tries it on hundreds of other services automatically. This is called credential stuffing, and it is responsible for the overwhelming majority of account takeovers.

If you use a different password everywhere, a breach at one site is contained to that site. That is the entire value proposition. Everything else is convenience.

There is a second benefit that gets far less attention: a password manager checks the domain before it fills anything. On a convincing copy of your bank's sign-in page it simply does nothing, which is a more reliable phishing detector than your own judgement — and it matters more now that scam listings and profiles come with convincing AI-generated photographs.

How they work, mechanically

A password manager keeps an encrypted database — the vault — that only unlocks with your master password. The important detail is where the decryption happens.

In any reputable manager, decryption happens on your device. The company stores an encrypted blob it cannot read, because your master password never leaves your machine. This is why they can say a breach of their servers would not expose your passwords. It is also why they cannot reset your master password for you.

That second part is not a marketing softener. It is a real constraint with real consequences.

What actually happens if you forget the master password

You lose the vault. Not "contact support and verify your identity". The data is encrypted with a key derived from that password, and nobody has a copy.

Most managers offer some recovery mechanism — an emergency kit, a recovery code, a trusted contact, biometric unlock on a device that is already authenticated. Set one up on day one, before you put anything important in. People skip this step and it is the single most common way the whole thing goes wrong.

Is the browser one good enough?

Chrome, Safari and Firefox all offer to save passwords, and for a long time the answer was clearly no. That has changed. Modern browser password managers do sync encrypted, do generate strong passwords, and do warn you about reused and breached credentials.

They remain weaker in three specific ways:

  • They are tied to the browser. Passwords saved in Safari are awkward to use on a Windows machine, and moving between ecosystems means exporting and importing.
  • They only store passwords. A dedicated manager holds recovery codes, software licences, passport numbers, WiFi keys and secure notes.
  • Sharing is limited or absent. If you need to give a family member the streaming login without messaging it in plain text, dedicated managers handle this properly.

If you live entirely in one browser on one platform and only need passwords, the built-in one is a reasonable choice. It is enormously better than reusing the same password everywhere, which is the comparison that matters.

The realistic objections

"It is a single point of failure." True, and worth taking seriously. But compare it honestly to the alternative: the same password across forty sites, which is forty points of failure that all fail together. A single well-protected point beats that.

"What if the company goes out of business?" Every credible manager offers export. Do it once a year, keep the file somewhere encrypted and offline. This also covers the case where you simply want to switch.

"I do not trust putting everything in one place." Reasonable. Some people keep their most sensitive credentials — primary email, banking — memorised and out of the vault entirely, and use the manager for everything else. That is a legitimate middle position.

Setting one up without spending a weekend on it

The mistake is trying to migrate everything at once. You will get bored around account fifteen and abandon it.

  1. Install it. Pick a long master password — a passphrase of four or five unrelated words beats a short jumble of symbols.
  2. Set up recovery immediately. Print the emergency kit if there is one.
  3. Add your email account first. Email is the master key to everything else, because password resets go there.
  4. Then your bank, then anything with a saved card.
  5. After that, stop. Let it capture the rest as you log in over the following months.

The important accounts are protected within twenty minutes. The long tail sorts itself out.

The thing that matters more

If you only do one security thing this year, make it two-factor authentication on your email account, not the password manager. Email resets everything else. An attacker with your email has your accounts regardless of how strong the individual passwords are.

Password manager second. Both is better. Neither is the position most people are in.

LO
Written by

Levin O'Connor

Levin O'Connor founded TechOrbitly and writes most of what appears on it: evidence-led guides on technology, health and everyday life, plus the free browser-based tools in the toolbox. Research over press releases — and a plain admission when the evidence is thin.

0 comments

Replying to
Never published. Used only for reply notifications.

No comments yet. Be the first to weigh in.

Keep reading

Related articles