← Privacy Guides

Accounts & identity

Choose and set up a password manager

Pick a password manager by checkable properties, protect it with a strong passphrase and two-factor sign-in, move your browser-saved passwords into it, and use its own checks to replace reused and leaked passwords.

  • Low threat
  • Time 1 to 2 hours
  • Difficulty Easy
  • Last verified

What this protects, and what it doesn't

Protects

  • Against password reuse: a leak at one site no longer opens your other accounts, because every account gets its own random password.
  • Against weak, guessable passwords, since the manager generates them for you.
  • Against some phishing: autofill only offers a password on the site it was saved for, so a lookalike domain gets nothing filled in.
  • Against losing access: an export, an emergency kit or emergency access lets you or someone you trust get back in.

Does not protect

  • Malware on your unlocked device. While the vault is open, software running as you can read what you can read.
  • A weak or reused master password. The whole vault is only as strong as the passphrase that unlocks it.
  • Phishing where you copy and paste the password by hand into a fake site.
  • Accounts that can be recovered by SMS or a guessable e-mail; fix the recovery path too.

Prerequisites

  • Your phone and computer, both with a screen lock and up-to-date software.
  • About an hour of quiet time for the first set-up, then a few minutes per account over the following weeks.
  • A pen and paper, or a printer, for the recovery details.

Step by step

  1. Choose a manager by properties you can check

    There is no single best product. Check these points in each vendor's own security documentation:

    • End-to-end encryption: the vault is encrypted on your device and the company cannot read it.
    • Independent audits published on the vendor's site, and either open source code or a published security design.
    • Export to a standard format, so you can leave if the product changes.
    • Passkey support, so the same place can hold your passkeys.
    • The devices and browsers you actually use.

    Examples, each with its own security documentation: Bitwarden (open source, end-to-end encrypted, audited at least once a year), KeePassXC (open source, a local encrypted .kdbx file you store yourself, audits), 1Password (published security design, account password plus a Secret Key), Proton Pass (end-to-end encrypted, audited), and the managers built into your system, Apple Passwords and Google Password Manager. The built-in ones are a large step up from reusing passwords; a separate manager helps if you mix Apple, Windows and Android devices.

  2. Create a master passphrase you can remember

    The master password is the one password you still type. Make it long rather than complicated: a passphrase of five or six random words is easier to remember and harder to guess than a short string of symbols. The password generator creates random passphrases in your browser.

    Never use this passphrase anywhere else. Write it down once, on paper, and keep the paper at home with your other important documents until you know it by heart.

  3. Turn on two-factor sign-in for the manager

    If your manager has an online account, turn on two-step login in its account settings, preferably with a passkey or hardware security key (see Passkeys and hardware keys), otherwise with an authenticator app. Bitwarden, for example, lists its methods on its two-step login page. Save the recovery code it gives you with your printed recovery details, not inside the vault itself.

  4. Prepare recovery and emergency access

    Decide now how you, or someone you trust, gets in if you forget the passphrase or are unable to.

    • 1Password creates an Emergency Kit: a PDF with your sign-in address, e-mail, Secret Key and a space to write the account password. Keep a printed copy somewhere secure; if you write the password on it, protect it like the vault itself.
    • Bitwarden has Emergency access (premium accounts): a trusted contact can request access, which is granted after a waiting time you choose unless you refuse.
    • KeePassXC has no account: keep a copy of the .kdbx file in your backups, and make sure someone you trust knows where it is and how to get the passphrase.
  5. Move passwords out of your browser

    Most managers can import a file exported from your browser. In Chrome, open the More menu, Passwords and autofill, Google Password Manager, then Settings, and next to Export Passwords choose Download file. Other browsers have a similar export in their password settings.

    That exported file is not encrypted: anyone who reads it sees every password. Import it into the manager straight away, then delete the file and empty the trash. Do not e-mail it or put it in cloud storage. Then delete the passwords from the browser and turn off the browser's offer to save passwords, so you keep one source of truth.

  6. Replace reused and leaked passwords first

    Use the manager's own check to decide what to fix first:

    • Apple Passwords: open Passwords, then Security. It flags easily guessed and reused passwords, and passwords that appear in known data leaks.
    • Google Password Manager: open it and choose Checkup on the left for passwords exposed in a data breach and weak ones.
    • Bitwarden: the vault health reports include Exposed, Reused and Weak passwords and Inactive 2FA (most need a premium account; the Data Breach report is free).
    • KeePassXC: Database Reports (Ctrl+Shift+R).

    Change leaked passwords first, then reused ones on your e-mail, bank and shopping accounts, letting the manager generate each new password. Where a site offers a passkey, take it instead.

  7. Use it every day

    Let the manager fill in passwords instead of typing them. If it does not offer to fill on a page where you expect it to, stop and check the address bar: that is often the sign of a lookalike site. Lock the vault when you step away, and set it to lock automatically after a few minutes.

Common mistakes

  • Reusing the master passphrase anywhere else.
  • Leaving the plaintext browser export in Downloads, in the trash or in a cloud folder.
  • Storing the manager's own recovery code inside the vault it recovers.
  • Keeping passwords in both the browser and the manager, so changes go out of sync.
  • Typing a password by hand when autofill refuses to fill it, without checking the address.

Going further

Move your most important accounts to passkeys and hardware keys, and keep an encrypted export of the vault in your backups. If your threat model is Medium or High, keep the vault on devices only you use, and consider a separate manager for work and personal accounts.