How do I manage passwords without losing my mind?
How to move from remembered, reused passwords to a manageable system, without doing all of it in one weekend.
- Difficulty
- beginner
- Time
- 1 hr
- Read
- 2 min
Short answer
Install a password manager, secure it with a strong master password you can remember, and let it generate unique passwords from then on. Don't try to change everything at once — change passwords as you use each site, starting with email, banking and anything holding payment details.
The reason people reuse passwords is that remembering unique ones is genuinely impossible at the scale modern life requires. A password manager removes the requirement to remember, which is the only workable solution — but the migration is what puts people off, and it doesn't have to happen all at once.
Step by step
- Choose a password manager and install it on every device you use.Any reputable one is enormously better than reuse. Cross-device sync is what makes it usable.
- Create a strong master password you can actually remember.Three or four random unrelated words is both strong and memorable. This is the one password you must remember.
- Write the master password down and store it somewhere physically secure.Losing it can mean losing everything in the vault. A sealed envelope somewhere safe is a reasonable precaution.
- Import saved passwords from your browser, then turn off the browser's own password saving.Two systems means confusion about which is current.
- Change the most important passwords first: email, then banking, then payment-storing accounts.Email first, because it can reset everything else.
- Change the rest gradually, as you log into each site.This is what makes migration achievable. Trying to do hundreds at once is why people abandon the attempt.
- Turn on two-factor authentication as you go.You're already in the security settings. It's the natural moment.
- Enable passkeys where offered.They can't be phished or reused, and most password managers store them alongside passwords.
Tips
- Password managers store more than passwords — recovery codes, software licences, passport numbers. Using it as a general secure store gets more value from it.
- Set up emergency access or a documented recovery process. If something happens to you, someone may need to get in.
- The security question fields are often the weakest link. Answer them with random text stored in the manager rather than real answers, which are frequently discoverable.
- Check the manager's breach-monitoring feature if it has one — it flags reused and compromised passwords automatically.
Common mistakes
- Trying to change every password at once — It's a huge job, so it doesn't get finished, and often gets abandoned entirely.
- A weak master password — It protects everything else. This is the one that has to be genuinely strong.
- Not recording the master password anywhere — Forgetting it usually means permanent loss of the vault.
- Running the manager and the browser's saved passwords together — You end up unsure which password is current for a given site.
Questions people ask
What if the password manager gets breached?
Reputable managers use zero-knowledge encryption, so the provider stores data they can't read without your master password. The risk is real but far smaller than the password reuse it eliminates.
What if I forget the master password?
With most managers, the vault is unrecoverable by design — that's what makes it secure. Which is exactly why you should record it somewhere physically safe.