openideurope.eu

How password managers work and why they are safe

A password manager keeps your logins in an encrypted vault that only your master password opens. How it works, the real risks and how to start in an afternoon.

Login securityPublished

A password manager keeps all your logins in an encrypted vault and fills them in for you. You remember one strong master password, and the manager creates and stores a different long password for every other account. For most people this is the single biggest step toward better account security.

How it works

  1. You create a master password. From it, the app derives an encryption key using a deliberately slow function, which makes guessing expensive.
  2. Your vault is encrypted on your device before anything is sent anywhere. The provider stores and syncs only scrambled data, an approach often called zero-knowledge.
  3. You unlock the vault with the master password, often with a fingerprint or face check on a device you have already set up.
  4. Autofill inserts the matching login when the site address matches the one saved. This is a quiet anti-phishing benefit, since a fake lookalike page does not match.
  5. Generated passwords are random and unique, so a leak at one service does not spread to the rest.

Some managers add a second secret that stays on your devices and is mixed into the key, so a stolen vault alone is not enough. This differs by product, so read the vendor’s security documentation.

Why it is safer than the alternatives

Approach Typical outcome
Same password everywhere One leak opens many accounts
Variations of one password Attackers try variations automatically
Notebook or sticky notes Fine at home, unusable on the road, easy to lose
Password manager Unique passwords, filled only on the right site, backed up and synced

It also helps with the advice in our guide to strong passwords: length and uniqueness, without the memorising.

Realistic risks

  • A weak master password. The vault is only as strong as the phrase that opens it. Use a long random passphrase.
  • A compromised device. Malware on your computer can capture what you type or see. Keep systems updated.
  • Phishing. Autofill helps, but never type a master password after clicking a link in an email.
  • Provider incidents. In 2022, LastPass confirmed that encrypted customer vaults had been copied. The ones with strong master passwords stayed protected, the weak ones were at risk. It is a good reason to choose a provider that publishes security audits and to use a long master password.
  • Single point of failure. Lose the master password and recovery kit and you lose the vault. Make a recovery plan, as described in account recovery.

Browser, phone or dedicated app

Browsers and operating systems now include solid password managers that also handle passkeys. Dedicated apps typically add cross-platform support, family and team sharing, emergency access and finer controls. Our guides compare the best password managers, European providers and free options.

Step by step: get started in an afternoon

  1. Choose a manager that fits your devices and budget.
  2. Create a long master passphrase. Five or six random words, used nowhere else. Write it on paper and keep it at home.
  3. Turn on 2FA for the manager and store its recovery kit offline.
  4. Install it on your computer, browser and phone.
  5. Import existing passwords from your browser, or add them as you log in.
  6. Fix the important ones first: email, banking, Apple or Google account. Replace them with generated passwords.
  7. Add passkeys where services offer them, and 2FA codes if your manager supports it.

Sharing and families

Most managers let you share selected logins without sending passwords in chat. For households and teams, see the guides for families and small businesses.

Is it safe to put everything in one place?

It feels risky, but compare it with the alternative. Reused passwords mean one leak opens many accounts, while a manager means an attacker would have to break strong encryption or your master password. For nearly everyone, the second scenario is much harder.

Three habits keep the risk low. First, a long, unique master passphrase. Second, 2FA on the manager itself, so that a stolen passphrase alone is not enough. Third, a device that stays updated and free of malware, because the manager can only protect what you do not hand over on an infected machine.

Audits and open source

Several providers publish independent security audits, and some make their code open source so that experts can inspect it. Neither is a guarantee, but they are good signs. Look for a published security whitepaper, a history of how the vendor handled past incidents and a clear explanation of what is encrypted and where.

What you should not store

Treat the manager as a place for logins, notes and documents that you want encrypted. Do not use it as the only copy of something irreplaceable, and keep the recovery kit for the manager itself outside the vault.

What happens to your data day to day

When you save a new login, the app encrypts it on your device and syncs the encrypted copy to your other devices. When you open a website, the extension compares the address with the saved entries and offers the matching login. Many managers also warn you about reused, weak or exposed passwords and about websites that offer passkeys. None of this requires you to trust the provider with your secrets, as long as the encryption is done on your side and your master password is strong.

Switching managers later

You are not locked in. Most managers export to a standard file, so you can move to another product if prices or features change. Delete the export file afterwards, since it holds your passwords in readable form.

Bottom line

A password manager is not magic, but it removes the habit that does the most damage, which is reusing passwords. Protect the master password, switch on 2FA, keep a recovery copy and let the manager do the work.

Frequently asked questions

What if my password manager gets hacked?

Well-designed managers store only encrypted vaults, so a server breach alone should not expose your passwords. The risk depends on your master password: a weak one can be guessed offline. The 2022 LastPass incident, in which encrypted vaults were copied, showed why a long master password matters.

What if I forget my master password?

Many managers cannot reset it, because they never see it. Some offer a recovery kit or a recovery option you set up in advance. Store that kit offline when you create the account.

Is the built-in manager in my browser or phone good enough?

It is much better than nothing and convenient. Dedicated managers usually add cross-platform use, sharing, emergency access and more control. Pick based on the devices you use.

Do password managers work with passkeys?

Many do. They can store and sync passkeys alongside passwords. Check that the one you choose supports the passkey features you need.

More in Login security