Accounts & Identity

Password Managers Explained

How password managers generate, store and fill unique passwords, what the master password protects, and how to choose and recover safely.

Plain-language summary

A password manager is an encrypted vault designed to remember account credentials so that each service can have a different, long password. The manager does not remove every risk, but it reduces the dangerous habit of reusing memorable passwords.

Why password reuse is the bigger problem

When one service is breached, attackers often try the same email-and-password pair elsewhere. Unique credentials limit that chain reaction. A manager makes uniqueness practical because the user does not need to memorize every generated password.

  • Use a unique vault password or passphrase.
  • Turn on MFA for the password-manager account when offered.
  • Keep recovery information and emergency access options current.

What the vault protects

A well-designed manager encrypts stored credentials and unlocks them only after authentication. Browser and device integration can fill credentials on matching websites, which also helps users notice when a look-alike domain does not match the saved login.

Built-in versus separate managers

Browsers, phones and operating systems often include credential managers. Separate services may add sharing, emergency access, cross-platform tools or administrative controls. The best choice is one you can keep updated, recover safely and use consistently.

Recovery deserves planning

Before moving every account into one vault, understand the recovery process. Save recovery codes in a protected offline location and confirm which devices remain signed in. Do not keep the only recovery secret inside the vault it is meant to recover.

Practical takeaway

A password manager is most useful when it supports unique credentials, MFA and a tested recovery plan. It is not a reason to ignore phishing, device security or account alerts.

Further reading

CISA includes password managers among its core recommendations for safer online accounts. See Secure Our World.

Sharing without exposing everything

Households and teams sometimes need shared access to selected accounts. Use the manager’s dedicated sharing feature rather than sending passwords by email or keeping a common unencrypted document. Shared access should be limited to the specific items needed and removed when the relationship or role changes.

Migration and portability

Before choosing a manager, understand how credentials can be exported, imported and deleted. Exports are often unencrypted files and should be protected and removed promptly after use. A recovery plan should include what happens if the service is unavailable or the subscription ends.

Autofill is a safety aid, not proof

A manager may refuse to fill a credential on a look-alike domain, which can warn of phishing. Still read the domain and context. Manually copying a password can bypass that protection, and a compromised device can observe information after the vault is unlocked.

What to review when choosing one

  • Independent security design and update history
  • MFA and passkey support
  • Clear recovery options
  • Encrypted export or safe migration process
  • Support for the devices and browsers you actually use
Educational scope: This page provides general information, not personalized incident response, legal advice, compliance advice or a guarantee of security.

Related reading