The idea of one app holding every password feels like putting all the eggs in one basket. Is that really safer than my current system (three passwords I reuse everywhere, apparently)?
Is it safe to keep all my passwords in a password manager, and which one?
- Replies
- 1
- Views
- 1
- Activity
-
@marco_r Squire OP#1
-
@alexk Knight#2
Yes, and your current system is the actual risk, because one leaked site gives an attacker the other two.
Why a manager is safer despite the "one basket": the vault is encrypted with a key derived from your master password, on your device, before it goes anywhere. The company cannot read it, and a thief who steals the encrypted file still has to break your master password. So the basket has a very good lock, and it lets every site have a different, long, random password, which is the thing that actually protects you.
How to do it well:
- One long master passphrase you never use anywhere else: four or five random words is easier to remember and stronger than "P@ssw0rd2026!".
- Turn on two-step sign-in for the manager itself.
- Save the recovery kit or emergency code somewhere physical.
- Let it generate new passwords as you log into sites over the next month; do not try to migrate everything in one evening.
- Use its breach alerts and change what it flags.
Which one: the built-in ones (Apple's Passwords app, Google's) are fine if you live in one ecosystem. Bitwarden is the usual recommendation for something independent and cheap or free; 1Password is the polished paid option. Avoid anything you cannot export from, and avoid browser extensions from companies you have never heard of.
Join the conversation
Sign in or create an account to reply.