How do I start using a password manager?
Setting one up, migrating existing passwords gradually, and the master password and recovery that make it safe.
- Difficulty
- beginner
- Time
- 1 hr
- Read
- 2 min
Short answer
Choose a reputable manager, set a long unique master password you can remember, and save the recovery key somewhere physical. Then migrate gradually — change passwords as you log into each site rather than all at once.
A password manager is the single most effective security improvement most people can make, because it makes unique passwords practical. Reused passwords are what turn one breach into many, and no amount of memory can produce unique ones at scale.
What you'll need
- A password manager (optional)
- Somewhere physical for the recovery key (optional)
Step by step
- Choose a reputable, well-established manager.Built into your browser or operating system, or a dedicated cross-platform one. Any of them is dramatically better than reusing passwords.
- Create a long, unique master password.Several unrelated words is easier to remember and harder to crack than a short complex string. This is the one password you must remember.
- Save the recovery key somewhere physical.Printed and stored securely. Most managers cannot recover your data without it, and losing access to everything is worse than the risk of storing it.
- Turn on two-factor authentication for the manager itself.It holds everything, so it deserves the strongest protection you can give it.
- Import existing saved passwords.Browsers can export them. It gives you an immediate inventory of what you have and reveals how much reuse there is.
- Migrate gradually rather than all at once.Change each password to a generated one as you next log in to that site. Trying to do hundreds in one session is why people abandon the effort.
- Prioritise the important accounts.Email first, since it is the recovery route for everything else. Then banking, then anything holding payment details.
- Install it on every device and in the browser.The convenience is what makes it stick. Having to look passwords up manually on a phone is how people revert to old habits.
Tips
- Passkeys are gradually replacing passwords entirely on some services and are more secure. Password managers increasingly store them too.
- Store more than passwords — recovery codes, software licences, wifi passwords, passport details. Anything you would otherwise write on a note.
- Set up emergency access if the manager offers it, so a trusted person can reach your accounts if something happens to you.
Common mistakes
- Not saving the recovery key — Most managers cannot recover your vault without it. Losing the master password then means losing every password at once.
- Trying to change every password in one session — It is tedious enough that most people give up partway. Changing them as you log in spreads it over weeks and actually completes.
- Using a short master password — It protects everything else. Several unrelated words is both easier to remember and considerably stronger than a short complex string.
Questions people ask
Is it safe to keep all my passwords in one place?
Yes, and it is far safer than the alternative. A well-implemented manager encrypts everything with your master password, and unique passwords per site contains any breach to that one site.
What happens if I forget my master password?
For most managers, the vault cannot be recovered without the recovery key — which is why saving it somewhere physical at setup is essential.