Over 80% of data breaches involve weak or reused passwords. If you're still reusing passwords, saving them in your browser, or writing them on sticky notes, a password manager is the single highest-impact security change you can make. This guide walks you through choosing one, setting it up, and migrating your entire digital life into it.
We recommend Bitwarden (free, open-source, audited) or 1Password (paid, excellent family sharing). Both use AES-256 encryption and have been independently security-audited. Avoid relying on your browser's built-in password manager — it's tied to your browser account, often lacks strong encryption, and doesn't work across all apps. Download the app from the official website, not a third-party source.
Your master password is the one password you'll need to memorize — it unlocks everything else. Create a passphrase of 4–6 random words, like correct-horse-battery-staple (but pick your own). Aim for at least 16 characters. Don't use personal info, song lyrics, or quotes. Write it down on paper and store it in a physically secure location (a locked drawer, not your desk). Never store your master password digitally.
Install the official browser extension for your primary browser (Chrome, Firefox, Brave, Safari) and the mobile app on your phone. These let the password manager autofill credentials on websites and in apps. Only install from official sources — the password manager's website or your phone's official app store. After installation, log in with your master password and enable biometric unlock (fingerprint or face) on your phone for convenience.
Most password managers can import passwords from your browser or another manager. In Chrome: go to passwords.google.com → Settings → Export passwords (this creates a CSV file). In your password manager, find the Import option and upload that CSV. After importing, immediately delete the CSV file — it contains all your passwords in plain text. Also delete the passwords from your browser's built-in manager and disable the browser's "Save passwords" feature so it doesn't compete with your new manager.
Most password managers have a "Vault Health" or "Password Audit" feature that flags weak, reused, or breached passwords. Run this audit now. Start with your most critical accounts — email, banking, and social media — and use the built-in password generator to replace each one with a unique, random password of at least 16 characters. You don't need to memorize any of these. The password manager remembers them for you.
Most password managers let you designate a trusted contact who can request access to your vault after a waiting period (e.g., 72 hours). This is critical in case of emergency — if you're incapacitated or pass away, your family needs access to accounts, utilities, and financial services. In Bitwarden: Settings → Emergency Access. In 1Password: set up a Family account and share a Recovery Kit with a trusted person stored in a sealed envelope in a safe.
Your password manager vault is the single most valuable target on your device. Protect it with 2FA using an authenticator app (not SMS). In Bitwarden: Settings → Two-step Login → Authenticator App. This means even if someone steals your master password, they still can't open your vault without the 2FA code from your phone. Store the 2FA recovery code on paper in your physically secure location — not inside the password manager itself.
From now on, every time you create a new account or update a password, do it through the password manager. Let it generate the password. Let it autofill the login. Never type a password by hand from memory again. Also store secure notes for things like Wi-Fi passwords, software license keys, and security questions. The more you use it, the more secure your entire digital life becomes. Within a week, it becomes second nature.
In a one-on-one session, we can walk through the full setup together — importing your passwords, replacing weak ones, configuring 2FA, and making sure your vault is properly secured and backed up.