Password Managers: The Objections, Answered
Password managers have a public relations problem. They are the single most effective security improvement available to an ordinary person, and almost everyone who has not adopted one gives the same two reasons: it seems complicated, and putting every password in one place feels like a bad idea.
Both objections deserve a straight answer rather than a lecture.
The single-basket objection
The concern is reasonable on its face. The answer is that you already have a single point of failure, and it is worse than a password manager.
If you reuse passwords, or use variations on a theme, then one breach at any site exposes the rest. This is not hypothetical: credential-stuffing attacks exist precisely because reuse is so common. Your email account is an even larger single point of failure, since it can reset almost every other account you own.
A reputable manager encrypts your vault on your device before anything is uploaded. The provider stores a blob it cannot read. That is a genuinely different risk profile from reusing one memorable password across forty sites.
The quiet benefit nobody mentions
The strongest argument for a password manager is not password strength. It is phishing resistance.
A manager fills credentials based on the domain. Land on a convincing replica of your bank and the manager simply does nothing, because the address does not match what it has stored. That silence is a warning you get for free, at exactly the moment you need it, without having to inspect anything yourself.
Human vigilance fails eventually. Everyone is tired sometimes. Domain matching is not.
Choosing one
The category is mature enough that most reputable options are fine. What matters:
- End-to-end encryption, with the vault encrypted before it leaves your device. This is table stakes; verify it rather than assume it.
- Independent security audits, published rather than merely referenced in marketing copy.
- Export that actually works. If you cannot get your data out in a standard format, you are locked in.
- Passkey support. The direction of travel is away from passwords entirely, and your manager should already handle them.
- It works everywhere you do. A manager you avoid because it is awkward on your phone provides no protection.
The manager built into your browser or operating system counts. It is meaningfully better than reuse, it is already installed, and for many people it is the right answer. Dedicated tools win on cross-platform support, sharing and organisation.
Setting it up without losing a weekend
The mistake is trying to migrate everything on day one. You will stall halfway and abandon it.
- Secure the master password properly. Four or five unrelated words are strong and memorable. Write it down and store the paper somewhere safe. This is the one password you cannot recover.
- Turn on two-factor authentication for the vault itself.
- Fix the important accounts first. Email, then banking, then anything holding payment details. That is perhaps ten accounts and an hour of work.
- Let the rest arrive on their own. Every time you log in somewhere, save it and change the password then. Within a month the vault fills itself.
- Run the built-in audit. Most managers flag reused and breached passwords. Work down that list when you have a spare ten minutes.
What about passkeys?
Passkeys are better, and where a site offers one you should take it. But adoption is partial and will stay partial for years. A password manager is what carries you through the long transition, and it is where your passkeys will live anyway.
Adopting one is not a security project. It is an afternoon, most of which is spent on ten accounts that actually matter.