Password managers
Quick answer
A password manager generates and stores a different strong credential for every service, protected by one passphrase the user memorises. It addresses credential reuse, which is the mechanism that turns a breach of one service into unauthorised access to many.
Passwords fail for a structural reason rather than a careless one. A person cannot memorise several dozen long, unrelated strings, so they do what is possible: reuse one password across services, or vary it predictably. Attackers rely on exactly this. Credentials exposed in a breach of one service are tried automatically against hundreds of others — a technique called credential stuffing — and the attempts succeed often enough to be worth automating.
A password manager removes the memory constraint. The software generates a long random credential for each service, stores it encrypted, and fills it in on request. The user memorises one passphrase, which is used to derive the key that decrypts the store.
How the protection works
- The vault
- An encrypted file or record containing the stored credentials. Without the key it is unreadable, including to the service provider in products designed on a zero-knowledge basis.
- The master passphrase
- The one secret the user holds. It is not stored anywhere by a well-designed product, which is why it generally cannot be reset — only the vault can be discarded and rebuilt.
- Key derivation
- A deliberately slow calculation that converts the passphrase into an encryption key, so that guessing attempts against a stolen vault are expensive rather than instantaneous.
- Domain matching
- The manager fills a credential only on the site it was saved for. This is the quiet benefit: a convincing imitation of a bank's site at a different address receives nothing, because the manager does not recognise it. See phishing.
- Second factor
- A further proof required alongside the passphrase to unlock or sync the vault.
The objection, stated fairly
Placing every credential in one store concentrates risk, and the concern is reasonable. Two things answer it. First, the alternative is not a safer arrangement but a worse one: reused passwords are already a single point of failure, with the difference that the failure is silent and outside the user's control. Second, the vault is encrypted, whereas memory and habit are not — a breach of the manager's servers exposes ciphertext, not credentials, provided the passphrase is strong and the design is sound.
What remains true is that the passphrase and the recovery arrangements become critical. A long passphrase, used nowhere else, and a recovery method the user has actually tested, are the two things that make the concentration acceptable.
Choosing a passphrase
Length contributes more than character variety. Several unrelated words chosen at random are both easier to remember and harder to guess than a short string with substitutions. The one requirement that admits no exception is that the passphrase is used for nothing else.
The three places a manager can live
| Type | Vault location | Main consideration |
|---|---|---|
| Built into the browser or operating system | Synced with the platform account | No cost, no extra software; tied to one ecosystem and to the security of that account |
| Dedicated service | Provider's servers, encrypted | Works across platforms and browsers; the provider becomes a party worth evaluating |
| Local or self-hosted | A file the user controls | No third party; syncing and backup become the user's responsibility |
All three are substantially better than reuse. Readers who will not adopt a separate product should still turn on the one already built into their browser or phone rather than continue reusing credentials.
Starting from an existing set of passwords
Adopting a manager does not require changing fifty passwords in an afternoon, and attempting that is the most common reason the attempt is abandoned. A workable sequence is to install the manager, let it capture credentials as they are used over a few weeks, and change passwords only in order of consequence. Primary email comes first, because it is the reset channel for everything else. Then banking and government services, then anything holding payment details, then the rest as they come up.
Most managers include a review that identifies reused and weak entries, which turns the remainder into a finite list rather than an open-ended task. Old accounts that are no longer needed are better closed than re-secured.
Multi-factor authentication alongside it
A password manager addresses what happens when a credential is stolen in bulk. Multi-factor authentication addresses what happens when one is stolen individually. The two are complementary, and on accounts that control others — primary email above all — both should be in place, since email is the reset channel for nearly everything else.
Not all second factors are equal. Codes from an authenticator application are stronger than codes sent by text message, because text messages can be intercepted or redirected through number transfer. Hardware keys and passkeys are stronger again, because the proof is bound to the site's real address and cannot be handed to an imitation. The Australian Cyber Security Centre explains multi-factor authentication and its forms at cyber.gov.au.
Passkeys
A passkey replaces the password with a cryptographic key pair: the private half stays on the device or in the manager, the public half sits with the service, and authentication is a challenge the private half answers. There is nothing to type, nothing to reuse and nothing to hand to a fraudulent site. Adoption is growing and incomplete, so for the present most people will hold a mixture of passkeys and passwords, and a manager that stores both avoids keeping two systems.
Managers bundled with security software
Password management is commonly included in antivirus subscriptions. The questions worth asking are whether the bundled manager works in the browsers and on the devices actually used, whether it supports a second factor, and how the data is exported if the subscription lapses. Export matters most: a manager that cannot produce a portable copy of its contents makes leaving expensive. What any particular product includes is a matter for the vendor's own documentation, and the entry on Norton AntiVirus Plus records only what is stated there.
Key terms on this page
- Credential stuffing
- Automated testing of credentials from one breach against many other services.
- Zero-knowledge
- A design in which the provider cannot read what it stores.
- Key derivation function
- A slow calculation turning a passphrase into an encryption key.
- Passkey
- A cryptographic credential bound to a specific site, used instead of a password.