Accounts

How to Choose and Use a Password Manager

A password manager is not just a vault. It is a system for using unique passwords, recovering safely, and reducing account emergencies.

Why a password manager matters

Password reuse is dangerous because one breached site can expose accounts on other sites. A password manager helps by creating and storing unique passwords for every account. You remember one strong master password, and the manager remembers the rest.

The goal is not perfection. The goal is to stop using the same password across email, banking, shopping, hosting, and social accounts.

What to look for

Choose a password manager with clear security documentation, active updates, export options, multi-factor authentication, device support you actually need, and a recovery process you understand. A polished interface is helpful, but recovery and trust matter more.

Make sure you can export your vault in an emergency. Exported files are sensitive, so store them carefully or delete them after migration. A manager that traps your data is not a good long-term choice.

Create a strong master password

Your master password should be long, unique, and memorable. A passphrase made from several unrelated words can be easier to remember than a short string of symbols. Do not reuse a password from another account. Do not store the master password inside the same vault it unlocks.

Write recovery information down and store it somewhere physically secure. This may feel old-fashioned, but it protects you from losing access if your phone breaks or your email account is locked.

Turn on multi-factor authentication

Enable multi-factor authentication for the password manager account and for your most important accounts. Authentication apps or hardware security keys are often stronger than SMS, though any second factor is usually better than none.

Save recovery codes offline. Many account lockouts happen because someone enabled stronger security but forgot to keep backup codes.

Clean up the vault gradually

Do not try to fix every password in one day. Start with email, banking, cloud storage, social accounts, phone carrier, domain registrar, hosting account, and tax or government accounts. Replace reused passwords with unique generated ones. Then work through lower-risk accounts over time.

Delete duplicate entries, label shared family accounts clearly, and keep notes minimal. A vault full of old clutter becomes harder to trust.

Use autofill with attention

Autofill is convenient, but pay attention to the domain before filling credentials. A password manager can help reveal phishing because it should not offer to fill a password on the wrong domain. If a login page looks strange and the manager does not recognize it, pause before typing anything manually.

Family and emergency planning

For families, use a plan that supports shared vaults rather than sending passwords through chat. Store shared streaming, utility, or household passwords in shared folders. For emergency access, follow the manager's official process or document a safe handoff method for someone you trust.

Bottom line: Pick a password manager you can recover, protect it with a strong master password and multi-factor authentication, then replace reused passwords starting with your most important accounts.