Advertising disclosure: vardenis.online is funded by partner links. If you buy through a link marked “Partner link”, we may earn a commission — at no extra cost to you. Learn more
vardenis.online

Password managers: why and how to use one

A password manager is one of the most effective security improvements you can make, and good options exist at every price, including free.

Diagram: a master password known only to you unlocks an encrypted vault, which holds a different unique password for email, online banking and shopping accounts.
One strong master password protects a vault of unique passwords. Original illustration by vardenis.online.

The problem: password reuse

When a website is breached, attackers try the leaked email and password combinations on other sites. This is called credential stuffing. If you use the same password everywhere, one breach can expose your email, shopping and even banking accounts.

How a password manager works

A password manager keeps your logins in an encrypted vault unlocked by one master password (and ideally a second factor). Reputable managers encrypt the vault on your device, so the provider cannot read your passwords. The manager generates long random passwords and fills them in automatically, so you don’t have to remember them.

Types of password manager

TypeExamples of where you find itConsiderations
Built into browser or operating systemBrowser password managers, Apple Passwords / iCloud Keychain, Google Password ManagerFree and convenient. Works best if you stay within one ecosystem.
Standalone serviceDedicated password manager appsWorks across browsers and platforms, often with secure sharing. Usually a subscription.
Bundled with a security suiteIncluded in some antivirus plansOne bill. Check export options in case you change suite later.
Offline / self-managedLocal vault filesFull control, but you are responsible for backups and syncing.

Setting one up safely

  1. Choose a long master passphrase, for example several random words, that you don’t use anywhere else.
  2. Turn on multi-factor authentication for the password manager account.
  3. Set up and store the recovery method (recovery code or emergency kit) somewhere safe and offline.
  4. Start with your most important accounts: email, banking, then everything else. Change reused passwords as you go.
  5. Consider passkeys where websites offer them. They replace passwords with cryptographic keys that can’t be phished.

Common worries

“Isn’t it putting all my eggs in one basket?” In practice, a well-protected vault with unique passwords is far safer than reusing a few memorable passwords, which is what most people do without a manager. Protect the vault with a strong passphrase and MFA.

This guide contains no partner links. It reflects general good practice as of 5 October 2026. For product-specific details, the vendor’s own documentation prevails. Illustrations are original works by vardenis.online. Corrections: info@vardenis.online.

Sources

  1. UK National Cyber Security Centre, “Password managers: using browsers and apps to save passwords”. ncsc.gov.uk
  2. ENISA, cyber hygiene. enisa.europa.eu
  3. FIDO Alliance, passkeys. fidoalliance.org
  4. Have I Been Pwned. haveibeenpwned.com