We use cookies for ads and analytics to support our work. You can accept or reject these non-essential cookies. Cookie policy.
Set up a password manager the right way: pick a tool, build your vault, generate strong passwords, enable autofill and 2FA, and migrate accounts safely.

A password manager is the highest-impact security upgrade most people can make in an afternoon: it creates a long, unique password for every account and fills it in for you, so one site's breach can't unlock the rest of your digital life. This guide walks through choosing a manager, building your vault, and migrating your accounts without ever locking yourself out.
Almost any reputable password manager beats reusing passwords, so prioritize fit over feature checklists. The main decision is where your encrypted vault lives and how it syncs between your devices.
| Type | Examples | Best for |
|---|---|---|
| Cloud-synced | Bitwarden, 1Password, Proton Pass | Most people using multiple devices |
| Local-first | KeePassXC | Power users who want full control of the vault file |
| Built-in | Apple Passwords, Google Password Manager | Single-ecosystem users on a budget |
Look for end-to-end encryption, a published security audit, passkey support, and open-source code if you want independent verification. Avoid any tool that can read your passwords on its own servers.
After installing, you'll set one master password. It is the only password you must memorize, and with most managers it cannot be recovered, so make it both strong and unique.
Store that recovery kit on paper somewhere physically secure, such as a home safe.
Install the browser extension and mobile app, sign in, then enable the platform autofill setting so the manager can offer to fill and save credentials.
From now on, whenever you create or change a password, let the manager generate a random string of at least 16 characters. You never need to see or type it again.
Don't try to fix everything at once. Import what you can, then replace weak passwords in priority order.
A password manager protects your passwords; two-factor authentication (2FA) protects your accounts even if a password leaks. Enable it on every account that supports it.
Decide where you want your encrypted vault to live, then download the official app from the vendor's site or your device's app store. Cloud-synced managers like Bitwarden, 1Password, or Proton Pass are easiest because they sync automatically across your devices.
Install both the desktop browser extension and the mobile app so your passwords follow you everywhere.
Set one master password that unlocks the vault. Use a passphrase of four to six random words rather than a short, complex string, it is stronger and far easier to remember.
During setup most managers generate a recovery key or emergency kit. Write it down or print it, then store it somewhere physically secure such as a home safe.
This is your only way back in if you forget the master password, and it cannot be regenerated later.
Turn on the autofill setting so your manager can fill and save logins automatically.
Import your existing logins by exporting them from your browser or old manager as a CSV file, then importing that file. Delete the CSV and empty your trash immediately afterward, it stores passwords in plain text.
Work through your accounts starting with email and banking, replacing each weak password with a generated string of at least 16 characters.
Enable two-factor authentication on every important account, preferring an authenticator app, passkey, or hardware key over SMS codes.
Where sites offer passkeys, adopt them, they replace passwords with a phishing-resistant key your manager can store and sync. Save any backup codes in your vault.
Yes. Reputable managers use end-to-end encryption, so your passwords are encrypted on your device with a key only you hold and even the company cannot read them. The far bigger risk is reusing weak passwords, which a manager eliminates.
With most zero-knowledge managers the company cannot reset it for you. You will need the recovery key or emergency kit generated during setup, which is why you should save it somewhere physically secure the day you sign up.
Browser managers are convenient and much better than reusing passwords, but a dedicated manager works across every browser and device, supports secure sharing, and adds breach monitoring and passkeys more consistently.
Not when the vault is end-to-end encrypted and protected by a strong master password plus two-factor authentication. Centralizing them lets you make every password long and unique, which is far safer than memorizing a handful of weak ones.
No. Free tiers from reputable providers are secure and enough for most people. Paid plans add extras like family sharing, large file storage, and emergency access, but they are not required for strong security.
Export your data as a CSV, import it into the new manager, then delete the CSV file and empty your trash. Verify a few logins work before removing the old app.
TechTools is our free, no-signup suite of fast utilities. Jump straight to Text Tools and get it done in seconds.
Share quick feedback - it's anonymous and separate from comments.
Comments
No comments yet - be the first to share your thoughts.
Leave a comment