Password managers: why you need one and how to actually start
Nobody can remember thirty different passwords, which is why almost everyone uses the same three. A password manager solves that, and you probably have one installed already.
- Level
- principiante
- Time
- 20 minutes
- What you need
- Your phone, and half an hour of calm
Everyone repeats the same rule: a different password for every site. Nobody explains how you are supposed to remember thirty of them. So we end up using three or four, always the same, with a different number stuck on the end.
The problem is not laziness, it is that human memory is not built for that job. A password manager takes the job away from your memory, and the good news is that you already have one installed: it is inside your phone and inside your browser, for free.
Password manager: a kind of locked address book where your device keeps all your passwords for you, and types them in when needed. Master password: the only one you have to remember yourself, the one that opens the book. Encryption: the transformation that makes the contents unreadable to anyone without that key, including the company providing the service.
Why reusing a password is the real danger
The problem is not somebody guessing your password. The problem is data breaches: every year dozens of sites are broken into and lists of email addresses and passwords end up for sale. Your address has, in all likelihood, been in one of those lists for years.
From there the attacker’s job is mechanical: take your email and the password stolen from some random site, and try them on a hundred other services. If you reused it, they are in. No skill required, it is a program grinding through lists.
That is why the only defence that works is that a password stolen from one site opens nothing else. And you only get that by having a different one everywhere, which means having a manager.
You can check right now whether your address has already turned up in a breach: Have I Been Pwned does it for free, from your email address.
Start with what you already have
Before installing anything, open what is already there. It works well, it is free, and it is enough for most people.
- On iPhone: there is a Passwords app, with a key icon. Open it, it asks for your code or your face, and inside you will find every password the phone has saved over the years.
- On Android: open Chrome, tap the three dots at the top right, then Passwords and autofill > Google Password Manager.
- From a computer, the same list opens at passwords.google.com with your Google account.
- Look at how many there are. The usual surprise is that there are far more than you remembered.
The check that changes your day
Both managers have a feature that does the work for you: it tells you which passwords are weak, which you reused and which have appeared in a breach.
- On iPhone: in the Passwords app tap Security. The problems appear as a list, one per line.
- On Android, in Google Password Manager, tap Password Checkup.
- Do not try to fix everything in one afternoon: that is the road to giving up. Do this instead: fix three today, and pick the right three.
The right three are always the same, in this order: your email account (because everything else can be reset from there), your bank, and the shop where your card is saved and you buy most often. The rest can wait until next week.
A password manager does not "send your passwords to someone". They are stored encrypted, unreadable without your key, and not even Apple or Google can read them. The real risk is not the manager: it is having the same password on twenty sites, which is the situation right now.
The master password, the only one you keep in your head
One password stays in your memory: the one that opens the manager. It needs to be long, and the simplest way to have it long and memorable is a phrase. Four unrelated words, perhaps with a reference only you understand, are far stronger than “Pa$$w0rd!” and infinitely easier to recall.
Write it on a piece of paper and keep it at home, in a drawer. It sounds like heresy, but it is not: a burglar going through your drawer is a remote possibility, a program grinding through stolen password lists is a daily certainty. We wrote the full method in how to create a password you can actually remember.
And if I want something more
The built-in manager has one limit: it is tied to its own world. If you have an iPhone and a Windows computer, or you want to share some passwords with your partner, a standalone manager makes sense. The names you will hear most are Bitwarden, 1Password and Proton Pass; the first has a free plan that is more than enough for one person.
It is not a necessary step to get started. Start with what you have, and think about switching in six months, once the new habit has settled.
Open the manager already in your phone, run the security check, and change three passwords today: email, bank, and the shop you buy from most. It takes twenty minutes and removes the most concrete risk you run online. The rest you fix gradually, whenever you happen to sign in somewhere.
The next step, worth even more, is turning on two-step verification: from then on a stolen password on its own is no good to anyone. And if you are curious where this is all heading, passkeys are the system that will retire passwords over the next few years.