Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Guides

Do you need a password manager?

Reusing passwords lets one breach unlock all your accounts. Here is how password managers work and how to pick one safely.

By · Published · Updated · 10 min read

Do you need a password manager?

When a site is breached, criminals try the leaked email and password on thousands of other sites. If you reuse passwords, one breach can unlock your email, bank and shopping accounts. A password manager fixes this.

What a password manager does

  • Creates a long, unique password for every site.
  • Stores them in an encrypted vault, protected by one master password or passkey.
  • Fills them in automatically — and only on the real site, which helps you spot fakes.

The UK's National Cyber Security Centre recommends using one.

How big is the password reuse problem?

Industry research backs up why reuse is such a risk. Dashlane's annual Global Password Health Score Report, based on aggregated data from millions of users and over 23,000 businesses, found that the share of reused, weak or compromised passwords has remained between 40% and 50% across regions worldwide, even as overall password health has slowly improved year over year (Dashlane/BusinessWire). Separately, compliance platform Drata notes that in 2024, 88% of basic web application attacks involved stolen credentials — underlining that weak or reused passwords remain one of the leading causes of breaches, despite years of warnings (Drata).

What official guidance says

The US National Institute of Standards and Technology (NIST), whose Special Publication 800-63B sets widely followed digital identity guidelines, has moved away from older advice such as forced periodic password changes and complex character requirements, since research shows these rules often push users toward weaker, more predictable passwords. Instead, current guidance emphasizes longer passphrases and only requiring a password change when there is actual evidence of compromise (PMMI).

NIST's guidance on password managers specifically recommends that systems support pasting into password fields (so password managers work properly), and advises users to:

  • Choose a long passphrase for the master password and protect it from being stolen.
  • Create unique passwords for every account, using a manager's built-in random password generator.
  • Avoid password managers that allow recovery of the master password, since any compromise of that recovery process can expose the entire vault.
  • Use multi-factor authentication to protect the vault itself (Specops Software).

Options

  • Built in: Apple Passwords / iCloud Keychain, Google Password Manager, Microsoft Edge.
  • Dedicated apps: Bitwarden, 1Password, Proton Pass, Dashlane and others.

How to choose safely

  • Download only from the official website or app store. This month, criminals spread fake LastPass downloads on GitHub that installed malware, SecurityWeek reported.
  • Turn on multi-factor authentication for the vault itself.
  • Pick a long master passphrase you have never used anywhere else.
  • Avoid tools that let you "recover" a forgotten master password through a simple email reset — NIST specifically flags this as a weakness, since it creates another avenue attackers can exploit.

Why passkeys are the next step

Password managers are increasingly also the easiest way to adopt passkeys — a newer, phishing-resistant sign-in method that replaces a typed password with a cryptographic key tied to your device. Major platforms including Apple, Google and Microsoft now support passkeys for many services, and most leading password manager apps can store and sync them alongside traditional passwords. Where a site offers a passkey option, using one removes much of the risk tied to password reuse and credential phishing entirely, since there is no shared secret for an attacker to steal from a breached website.

Getting started

Begin with your email account, then banking, then everything else as you log in. You do not need to change everything in one day.

What readers should do

  1. Pick one password manager — a free built-in option like Apple Passwords or Google Password Manager is a reasonable starting point if you are not ready to pay for a dedicated app.
  2. Secure the vault itself first. Set a long, unique master passphrase and turn on multi-factor authentication before importing any other passwords.
  3. Start with your most important accounts — primary email, online banking, and any account tied to password resets for everything else — then expand gradually.
  4. Let the generator do the work. Use the password manager's built-in generator to create long, random, unique passwords rather than inventing your own.
  5. Enable breach alerts if your chosen password manager offers them, so you are notified automatically if one of your stored logins turns up in a new breach.
  6. Only install from official sources. Download password manager apps directly from the vendor's website or your device's official app store, never from search ads, forum links, or third-party file-hosting sites.

Sources

When a password manager alone is not enough

A password manager removes the risk of reused passwords, but it does not protect you if you are tricked into typing your master password into a fake login page, or if malware on your device captures your keystrokes. That is why security guidance consistently pairs password manager use with multi-factor authentication and, where available, hardware security keys or passkeys — layered defences that remain effective even if one layer fails.

Why regulators and standards bodies keep pushing this advice

Password reuse is not a theoretical risk. Compliance platform Drata reports that in 2024, 88% of basic web application attacks involved stolen credentials, meaning the single biggest factor behind one of the most common categories of breach was not a sophisticated technical exploit, but a password that had already been compromised elsewhere and reused (Drata). Dashlane's Global Password Health Score Report, drawing on aggregated and anonymized data across its user base and more than 23,000 businesses, has consistently found that 40% to 50% of passwords in use worldwide are weak, reused, or already compromised, with only gradual improvement year over year despite over a decade of public warnings (Dashlane/BusinessWire).

This is why national cybersecurity guidance has converged on the same recommendation. The UK's National Cyber Security Centre explicitly recommends using a password manager for most people, arguing that the security benefit of unique, high-entropy passwords for every account outweighs concerns some people have about storing all their passwords "in one place" (NCSC). The logic is straightforward: the realistic alternative to a password manager is not perfect memorization of dozens of unique complex passwords — it is reuse, which is measurably far riskier.

How NIST's advice has changed — and why it matters to you

For years, common advice told people to change passwords every 90 days and to include a mix of symbols, numbers and capital letters. US government guidelines have since moved away from both practices. NIST Special Publication 800-63B, the federal government's digital identity guideline, now recommends against mandatory periodic password changes unless there is evidence of compromise, because research consistently showed that forced regular changes push people toward small, predictable variations of the same password (like appending "1," "2," "3") rather than genuinely new ones (PMMI). The updated emphasis is on length over complexity — a long, memorable passphrase is now considered stronger and more usable than a short password crammed with special characters.

This shift matters for password manager users specifically because it changes what a strong master password should look like: a long, unique sentence-like phrase that you have never used anywhere else, rather than a short string you try to make "complex" with substitutions.

A quick practical comparison of options

TypeExamplesCostBest for
Built-in / browserApple Passwords, Google Password Manager, Microsoft EdgeFreePeople who want the simplest possible starting point
Dedicated freeBitwarden (free tier), Proton Pass (free tier)FreeCross-platform users who want more control without paying
Dedicated paid1Password, Dashlane, Bitwarden PremiumPaid, usually subscriptionFamilies, power users, built-in breach monitoring and sharing features

Whichever category you choose, the security gain over password reuse is large; the differences between well-regarded options are mostly about convenience features, not fundamental safety.

Sources

Read next