Security & Privacy
How to Use a Password Manager
A friendly, jargon-free guide to using a password manager, covering setup, your master password, autofill, and the simple habits that keep accounts safe.
Security & Privacy
A friendly, jargon-free guide to using a password manager, covering setup, your master password, autofill, and the simple habits that keep accounts safe.
A password manager flips the hardest problem in personal security into an easy one: instead of memorising dozens of unique passwords, you memorise exactly one strong master password, and the app generates, stores, and autofills everything else behind AES-256 encryption. This guide covers choosing a manager, building a master password that actually resists cracking, wiring up autofill on your phone and browser, migrating your existing logins without a painful weekend, and the specific mistakes that quietly undermine people who think they are protected.
The right pick depends on your devices and budget far more than on marketing.
The common mistake here is chasing the theoretically "best" app. Any reputable, independently audited manager you will actually open every day beats a superior one you abandon after a week.
Your master password is the one secret the company usually cannot reset for you, so it has to be both memorable and genuinely hard to crack. Length beats complexity: a five- or six-word passphrase such as copper-lantern-drifts-past-quiet-harbor is far stronger and easier to type than Xk9$2m!. Modern managers then stretch that phrase with key-derivation functions like PBKDF2 (Bitwarden defaults to 600,000 iterations) or Argon2id, which slows any brute-force attempt to a crawl.
Do not store the master password inside the vault it unlocks, and do not drop it into a note on your phone. Both defeat the point.
Autofill is what makes a manager effortless, but you have to enable it in two places.
On iPhone or iPad: Settings > General > AutoFill & Passwords (on older iOS, Settings > Passwords > Password Options), then toggle on your manager. Turn off iCloud Passwords if you want a single source of truth.
On Android: Settings > Passwords, passkeys & accounts, then choose your preferred provider. The path varies by manufacturer and version; on some phones it lives under Settings > System > Languages & input > Autofill service.
In your browser: install the manager's extension and pin it to the toolbar. Then switch off the browser's own password saving so the two do not fight. In Chrome that is Settings > Autofill and passwords > Google Password Manager, where you turn off "Offer to save passwords."
Set the generator to at least 16 characters with symbols for any site you never type by hand. From then on, when you land on a login page, the extension recognises the domain and offers to fill. That domain check quietly protects you from phishing too, because it will not autofill a lookalike address like paypa1.com.
You do not need to convert every account at once. Work top-down.
Email is priority one, because it is the password-reset point for nearly everything else. Whoever controls your inbox can reset their way into your other accounts, so a unique, strong email password plus 2FA is the single highest-value change you can make.
A vault holding every password is a high-value target, so protect it harder than any individual account.
Yes, when it is a reputable manager using end-to-end, zero-knowledge AES-256 encryption, because the company stores only scrambled data it cannot read. The realistic risk is not the vault being cracked; it is a weak master password or missing 2FA, and both of those are fully in your control.
With true zero-knowledge managers like Bitwarden, 1Password, and KeePassXC, the company cannot reset it, so you fall back on your recovery code, Emergency Kit, or a designated emergency contact if you set one up. This is exactly why saving those recovery materials during setup is non-negotiable rather than optional.
Bitwarden's free tier is genuinely sufficient for most people, and Apple's or Google's built-in managers are fine within a single ecosystem. Paying (roughly $10 to $60 a year) buys conveniences like integrated 2FA, breach alerts, family sharing, and smoother cross-platform use, all worth having but none of them required to be secure.
They are complementary, not competing. Passkeys are more phishing-resistant and are the better choice on any site that supports them, but plenty of services still require a password. A good manager stores both and syncs your passkeys across devices, so you are covered either way.
Keep reading
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.