Cybersecurity · Explainer

Password managers explained: how they work and how to choose one

Password managers explained: how they create, encrypt and autofill strong passwords, how built-in and standalone apps compare, and how to choose one.

Metal padlock on a laptop keyboard circled by red and blue light trails

Key takeaways

  • A password manager creates, stores and fills in a unique password for every account, so you only have to remember one strong master password.
  • Many password managers encrypt your vault so only your devices can unlock it, which also means a forgotten master password may be impossible to reset.
  • Autofill only offers a password on the site it was saved for, so a login that won't fill in can be an early sign of a phishing page.
  • Built-in managers from Apple, Google and Microsoft suit people who mostly stay on one platform, while standalone apps work across more devices and browsers.
  • Protect the manager itself with a long passphrase and two-factor authentication, ideally a passkey or security key.

A password manager is an app that creates a strong, unique password for every account, saves it in an encrypted vault and fills it in for you, so the only password you need to remember is the one that unlocks the vault. It’s the simplest fix for password reuse, the habit that lets one leaked password open several of your accounts. Here’s how password managers work, how the built-in options compare with standalone apps, and what to check before you choose one.

What a password manager actually does

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) describes a password manager as a program that “generates, stores and even fills in all your passwords.” In practice, a modern one handles five jobs:

  • Generates long, random passwords when you sign up for something new.
  • Stores them in an encrypted vault, along with notes, card details and, increasingly, passkeys.
  • Fills them in on websites and apps through a browser extension or your phone’s autofill system.
  • Syncs the vault across your phone, tablet and computer.
  • Warns you about weak, reused or leaked passwords.

That combination is what makes strong passwords realistic. CISA’s Use Strong Passwords guidance asks for at least 16 characters and a different password for every account, which nobody can memorize across dozens of logins. NIST’s digital identity guidelines, SP 800-63B, back this up from the other side: websites must allow password managers and autofill, and should let you paste a password when autofill isn’t available.

Many password managers now store passkeys as well, the password replacement our passkeys explainer covers in detail.

How a password manager keeps your vault safe

The vault and the master password

Everything you save goes into an encrypted vault that syncs between your devices. Many password managers use end-to-end encryption, sometimes marketed as “zero-knowledge” design: the vault is locked and unlocked on your own devices, and the company stores only scrambled data it can’t read. Apple, for example, says passwords in iCloud Keychain are end-to-end encrypted even under its standard data protection setting, and Google says Chrome protects saved passwords with methods such as on-device encryption, depending on your operating system. Google Password Manager’s option to encrypt synced passwords so only you hold the key is off until you set it up, and it can’t be removed afterward.

The key to a standalone vault is your master password, sometimes called the primary or vault password. Day to day, most apps let you unlock with your face, fingerprint or device PIN instead of typing it. With built-in managers, access is tied to your Apple, Google or Microsoft account plus your device’s screen lock.

Autofill doubles as a phishing check

A password manager remembers the exact web address each password belongs to. Google explains that its password manager “matches passwords with the websites they are meant for, and not sites that look similar.” So if you land on a convincing login page and your manager doesn’t offer to fill anything in, treat that as a warning sign, not a glitch. It isn’t a perfect defense, since you can still copy and paste a password into the wrong site, but it catches the mistakes people make when they’re rushed. Our guide to spotting phishing covers the other red flags.

Breach and weak-password alerts

Most managers also run a health check. Apple’s Passwords app flags passwords that are easy to guess, reused across accounts or found in known data leaks. Google’s Password Checkup does something similar, and Google says Chrome checks an encrypted, obscured copy of your username and password against a list of known breached data rather than sending the real thing.

Built-in vs. standalone password managers

You probably already have a password manager, whether you use it or not. Apple, Google and Microsoft each build one into their devices or browsers, and standalone apps work across all of them.

Apple Passwords Google Password Manager Microsoft Password Manager Standalone apps
Where it works iPhone, iPad, Mac and Apple Vision Pro, plus Windows via iCloud for Windows Chrome on computers, Android phones, and iPhone or iPad Microsoft Edge and Windows settings Apps and browser extensions for most systems
Stores passkeys Yes Yes Yes Most major ones
Cost Included Included Included Some have free tiers; extra features often need a subscription
Main limitation Little help on Android Works best inside Chrome and Android Built around Edge; personal accounts only One more account to secure
Good fit for All-Apple households Chrome and Android users Windows and Edge users Mixed devices and browsers

Apple’s Passwords app arrived with iOS 18 and macOS Sequoia, and on a Windows PC, iCloud for Windows can fill your Apple passwords in Chrome or Edge. Microsoft’s version, Microsoft Password Manager, syncs through Edge when you sign in with a personal Microsoft account.

Examples of standalone managers include 1Password, Bitwarden, Dashlane, Keeper and Proton Pass. We name them to show what’s out there, not to rank them. CISA’s mobile security guidance lists several of these alongside the built-in options, without endorsing any.

How to choose a password manager

Rather than chasing a “best of” list, check each option against how you actually live:

  • Every device you use. If you have an iPhone and a Windows laptop, or share a tablet with someone on Android, a manager that only works well on one platform leaves gaps.
  • Every browser you use. Built-in managers work best in their own browser. Standalone apps offer extensions for the major ones.
  • Encryption and transparency. Look for end-to-end encryption and published results from independent security audits.
  • Protection for the vault itself. Your manager account should support two-factor authentication, ideally with a passkey or hardware security key. Our comparison of two-factor methods explains the options.
  • Passkey support. More sites offer passkeys every year, so your manager should create, store and sync them.
  • Recovery options. Find out what happens if you forget your master password or lose your phone before you move everything in.
  • Sharing. If you share streaming or utility logins with family, check how sharing works and whether everyone needs the same app.
  • An exit route. The FIDO Alliance’s Credential Exchange specifications are designed to move passwords and passkeys between managers securely. Support is still rolling out as of 2026, so check before you count on it.
  • Reputation. CISA suggests looking up password managers through trusted sources and reading reviews before you choose.

Setting one up without the headache

  1. Create a strong master password. CISA suggests a long passphrase of four to seven unrelated words. Don’t use it anywhere else.
  2. Turn on two-factor authentication for the password manager account, or make sure your Apple, Google or Microsoft account has it.
  3. Save your recovery details. If the manager gives you a recovery code or emergency kit, print it and store it somewhere safe at home.
  4. Import what you already have. Most managers can import passwords saved in your browser. If you export them to a file along the way, that file is usually unencrypted plain text, so delete it as soon as the import finishes.
  5. Fix your most important accounts first. Start with email, banking and your phone carrier, then work through anything the health check flags as reused or leaked.
  6. Add passkeys as you go. When a site offers one, saving it in your manager keeps everything in one place.

Try not to run two managers side by side, for example your browser and a separate app, or you’ll end up with outdated copies. Pick one and turn off password saving in the other.

The risks, honestly

A password manager concentrates a lot of value in one place, so it’s worth knowing what can go wrong:

  • A weak master password. If someone can guess or phish it and you have no second factor, they get everything. This is the risk you control most directly.
  • Attacks on the company. Password manager companies are prime targets, and encrypted vault data has been stolen from at least one before. Strong encryption and a long, unique master password are what keep stolen data useless.
  • Malware on your device. If your phone or computer is compromised while your vault is unlocked, the manager can’t fully protect you. Keep your devices updated; our guide to phone software update support explains why that matters.
  • Getting locked out. Losing both your master password and your recovery details can mean losing the vault.
  • Everything in one basket. Some managers can also generate two-factor codes. That’s convenient, but it means one vault holds both your password and your second factor.

For most people, these risks are still smaller than the risk of reusing passwords, where one breach can unlock many accounts.

The bottom line

A password manager turns strong, unique passwords from an impossible chore into something automatic. If you mostly stay on Apple, Google or Microsoft devices, the free built-in option is a solid start. If you mix platforms or browsers, a standalone app is usually the smoother fit. Whichever you pick, protect it with a long passphrase and a second factor, and add passkeys wherever sites offer them.

For more ways to lock down your accounts, browse our cybersecurity coverage and more plain-English guides on RedAndWhiteMagz.com.

Frequently asked questions

What happens if I forget my password manager's master password?

It depends on the manager. Many are designed so the company can't read or reset your vault, so recovery relies on a recovery code, emergency kit or trusted contact you set up in advance. Built-in managers are tied to your Apple, Google or Microsoft account, so recovery follows that account's own sign-in and recovery process.

Do I still need to change my passwords regularly?

Not on a schedule. NIST's current guidelines tell services not to force periodic password changes, but to require a change when there is evidence a password has been compromised. Change a password when your manager flags it as leaked or reused, or when a service reports a breach.

Is it safe to keep passwords in a notebook or spreadsheet instead?

A paper notebook kept at home is better than reusing the same password everywhere, but it can't create strong passwords, fill them in or warn you about fake sites. An unencrypted spreadsheet or notes file is riskier, because anyone or any malware that gets the file gets every password at once.

Can I share passwords with my family through a password manager?

Usually, yes. Apple's Passwords app supports shared groups with people in your contacts, Google Password Manager can share a password with members of your Google family group, and most standalone managers offer family or shared vaults. Only share what you need to, and never share a password you reuse elsewhere.

Sources

First published . Spotted an error? Read our editorial policy and tell us.

Contact RedAndWhiteMagz.com

Have a tech question or a story tip?

Spotted a new gadget, a scam making the rounds or a mistake in one of our guides? Tell us. We read every message and reply as quickly as we can.

Close-up of a black mechanical keyboard with glowing red backlit keys in a dark room