Password managers, and the objection everyone has
"All my eggs in one basket" is the right instinct and the wrong conclusion.
Updated 2026-09-26
The objection is always the same, and it is a reasonable one: *why would I put every password in one place?*
Because the alternative is worse, and it is worth understanding exactly why.
The one-basket answer
You already have one basket. It is your email account, and everything resets through it. Adding a password manager does not create single point of failure; it replaces a bad one with a good one.
And the realistic threat is not someone breaking the manager's encryption. It is credential stuffing: one site gets breached, your reused password is tried automatically against two hundred others, and something works. That happens constantly, to ordinary people, and a password manager ends it completely.
The eggs are in one basket either way. The question is whether the basket is a vault or a sticky note in your head reading Summer2019!.
What a good one does
Generates long random passwords you never see and never type.
Fills by domain. The quiet hero: on a lookalike phishing domain it simply will not offer to fill, and that silence is a better warning than anything you would have spotted by eye. More on that in fake login pages.
Encrypts on your device. The provider stores an encrypted blob they cannot read. This is why a breach of a password manager is serious but not automatically fatal.
Works everywhere you are, or you will stop using it.
Choosing
The honest answer is that the major ones are all fine and the one you will actually use beats the theoretically best one.
- Your browser's built-in manager — Chrome, Safari, Firefox. Free, already there, and genuinely
a large improvement on reuse. Weak if you move between browsers.
- Apple Passwords or Google Password Manager — free, well made, best if your household lives
entirely in one ecosystem.
- A dedicated manager — 1Password, Bitwarden, Proton Pass and similar. Cross-platform, family
sharing, secure notes, better recovery. Bitwarden has a real free tier.
What matters more than the brand: it is not a password manager you found in an advert, and it has been independently audited.
The master password
One password, and it needs to be good. Four or five unrelated words — long, memorable, and far stronger than a short string of symbols.
Write it down and put it somewhere physically safe. That is not bad advice here; burglars are not your threat model and forgetting it is.
Turn on two-factor for the manager itself.
Save the recovery kit. People lose access to their own vault more often than they are attacked, and it is a miserable way to spend a weekend.
Moving over without an awful afternoon
Do not try to do all of them.
1. Install it and set the master password. 2. Import whatever your browser has saved. One click, and it does most of the work. 3. Change the passwords for email, banking, and your phone account. Those three, today. 4. After that, change each one as you happen to log in over the next few months.
Within a few weeks the reuse is gone without a single dedicated session.
Our password checker tells you whether a specific password is already circulating in breach data. It runs in your browser and never sends the password anywhere.
Check a password Free, and it needs no account.