Skip to content
Stay Safe

Password managers: how to actually start

By Editorial Team Published 2 min read
os general tested 2026-09-09 retest 2027-03 by editorial team
Quick Fix
01 You already have one: iPhone/Mac use the built-in Passwords app; Android/Chrome use Google Password Manager. Turn it on and let it save and suggest strong passwords.
02 Then fix the accounts that matter most first — email, then banking — giving each a new, unique, generated password.
tested general · 2026-09-09

Reusing the same password everywhere is the number-one way ordinary accounts get taken over: one breached site hands attackers the key to all the others. A password manager fixes this by giving every account its own strong password that you never have to remember. And you almost certainly already have one.

Use the one you already have

  • iPhone / Mac: the built-in Passwords app (Settings > Passwords). It saves logins, generates strong ones, and autofills across Apple devices.
  • Android / Chrome: Google Password Manager (built into Chrome and Android settings) does the same.
  • Cross-platform / want independence: a dedicated manager like Bitwarden (has a solid free tier) or 1Password works across every device and browser.

Any of these is a massive upgrade over reused passwords. Start with whatever’s already on your phone; you can move later.

Don’t try to fix everything at once

The mistake that stalls people is trying to change 200 passwords in one sitting. Don’t. Do it in priority order:

  1. Email first — it’s the master key; a reset link for every other account lands here.
  2. Banking and finance.
  3. Anything with your card saved (shopping, subscriptions).
  4. Then let the manager quietly save the rest as you log in over the following weeks.

For each, let the manager generate a new random password — you don’t need to know it, only your one master password/PIN and phone unlock.

Turn on two-factor authentication too

A password manager plus two-factor authentication (2FA) on your key accounts is the combination that stops the vast majority of account takeovers. Turn on 2FA for email and banking at minimum — most managers can store the 2FA codes as well.

Protect the manager itself

  • Your master password is the one you must never reuse and never forget — make it a long passphrase.
  • Turn on 2FA for the password manager account.
  • Know the recovery options (recovery key/kit) and store them safely offline.

Frequently asked questions

Is it safe to keep all my passwords in one place?

Yes — reputable managers encrypt everything so even the provider can’t read it, and the alternative (reuse and sticky notes) is far riskier. The concentrated risk is outweighed by ending password reuse.

What if I forget the master password?

Most managers can’t recover it by design (that’s what makes them secure), so set up the recovery key and store it safely. Choose a memorable long passphrase.

Browser manager or a dedicated app?

The built-in browser/phone managers are good and free — start there. A dedicated app is worth it if you use many different browsers/platforms or want to share logins with family securely.

Sources