Security guide

Password Managers Guide

Create, Store, and Share Passwords Securely

Passwords protect nearly every aspect of digital life — yet reuse and weak patterns remain one of the weakest links in cybersecurity. A password manager fixes that.

The problem isn't passwords themselves. It's how people use them. Many still reuse the same password across dozens of sites or make only small variations:

Summer2026!Summer2026!AmazonSummer2026!Facebook

If one website suffers a breach, attackers test those credentials everywhere — a technique called credential stuffing, responsible for millions of compromised accounts every year. A password manager generates a different password for every account. You only need to remember one strong master password.

Why password managers are essential

A good password manager dramatically improves both security and daily experience online.

  • Generate long, random passwords instantly
  • Store every password inside an encrypted vault
  • Automatically fill login forms
  • Detect reused or weak passwords
  • Receive alerts when credentials appear in known breaches
  • Synchronize passwords across your devices
  • Store passkeys alongside passwords
  • Securely share credentials when necessary

How password managers work

Your credentials live inside an encrypted vault. When you create the vault, you choose a master password that derives the encryption keys protecting everything inside.

Modern cryptography typically includes:

  • AES-256 encryption
  • Argon2id or PBKDF2 for key derivation
  • Authenticated encryption to detect tampering

Because the vault is encrypted before storage or sync, reputable providers generally cannot read your passwords.

Once unlocked, your manager can:

  • Autofill usernames and passwords
  • Generate secure passwords
  • Save newly created credentials
  • Synchronize changes across devices
  • Store secure notes and passkeys

Benefits of using a password manager

Every account gets a unique password

If your Netflix password is stolen, it should not also unlock your email, banking, GitHub account, or cloud storage. Password managers make unique passwords effortless.

Strong password generation

Humans are poor at inventing random passwords. Managers generate high-entropy strings like uQ8!kL#7P2@wXf9$rZm4 — extremely difficult to guess or brute-force.

Automatic login

Password managers recognize websites and fill credentials automatically. Reputable managers typically autofill only on the correct domain, which also helps protect against phishing.

Password health reports

Many managers flag reused passwords, weak passwords, compromised credentials, missing MFA, and sites that support passkeys — helping you improve security over time.

Secure synchronization

Modern managers sync your encrypted vault across desktop, laptop, phone, and tablet so passwords stay available wherever you need them.

Partner tool

Browser-based generation with Passwords.lu

Sometimes you only need a strong password — not a full vault workflow. Passwords.lu runs generation directly in your browser. Passwords are not uploaded to servers; no account required.

Recommended workflow: generate on Passwords.lu, then immediately save in your password manager.

Open password generator
  • Strong password generator
  • Passphrase generator
  • Secure PIN generator
  • Password strength checker
  • Username generator
  • Hash generators (Argon2id, bcrypt, scrypt and more)
  • Educational security tools

Recommended password managers

Think in three layers: platform-built tools for stability, local open-source vaults for control, and cloud managers when you need powerful sync — accepting the extra server-side risk that comes with it.

Tier 1

Platform-built managers

Strong engineering, stable products — best default for most people

Apple and Google ship password managers with the operating system. They are backed by large security teams, receive continuous updates, and integrate passkeys, autofill, and breach alerts with minimal setup. If you live in one ecosystem, this is often the smoothest and most reliable choice.

Strengths

  • Polished UX with OS-level autofill and passkey support
  • Maintained by platform security engineers at scale
  • No separate subscription for core features
  • Stable sync through iCloud or your Google Account

Trade-offs

  • Tied to Apple or Google account and platform choices
  • Less flexible if you mix Windows, Linux, and mobile freely
  • Trust model depends on your cloud account security

Apple Passwords

Best for iPhone, iPad, Mac, and Vision Pro

Built into Apple platforms with secure storage, generation, security alerts, passkeys, and iCloud Keychain sync — no extra app required in an all-Apple household.

  • Deep OS integration and passkey support
  • Security alerts for known breaches
  • Excellent UX when you stay inside Apple's stack
Learn more

Google Password Manager

Best for Android and Chrome

Built into Android and Chrome with generation, autofill, Password Checkup, breach alerts, passkeys, and sync through your Google Account.

  • Convenient default on Android devices
  • Password Checkup and breach alerts
  • Works wherever you use Chrome
Learn more

Tier 2

Local open-source vaults

Maximum control — you own the encrypted file

KeePass stores your vault as a local encrypted database. Nothing requires a vendor cloud account: you decide where the file lives and how it syncs. The trade-off is UX — interfaces can feel dated compared with platform or cloud managers, and multi-device sync is DIY unless you add your own storage layer.

Strengths

  • Open source and auditable
  • No mandatory cloud account or subscription
  • Offline-first; vault file stays under your control
  • Large plugin ecosystem (KeePassXC, mobile ports, etc.)

Trade-offs

  • UI and onboarding less polished than platform tools
  • Sync across devices is manual unless you configure it
  • More setup work for families or mixed-device households

KeePass

Best for privacy purists and self-hosters

The original open-source model: one encrypted .kdbx file you can store on disk, USB, NAS, or sync through your own cloud. KeePassXC is a popular cross-platform fork with a more modern interface.

  • Completely free — no vendor lock-in
  • You choose storage and sync strategy
  • Ideal when the cloud is optional, not default
Learn more

Tier 3

Cloud-sync password managers

Powerful sync and sharing — highest server-side risk

Dedicated cloud managers like Bitwarden excel at cross-platform sync, family sharing, and team features. That convenience comes with a different threat model: your encrypted vault (and sometimes metadata) lives on someone else's servers. A breach or misconfiguration at the vendor is the main residual risk — which is why audits, open source, and a strong master password matter more here than anywhere else.

Strengths

  • Best cross-device sync out of the box
  • Family and organization sharing features
  • Works consistently across Windows, macOS, Linux, and mobile
  • Open-source options (Bitwarden) with public security audits

Trade-offs

  • Largest attack surface if the vendor is compromised
  • Encrypted vault backups can still be offline-cracked with weak master passwords
  • You must trust the vendor's crypto implementation and ops

Bitwarden

Best cloud option for cross-platform users

Open-source software, end-to-end encrypted sync, passkey support, independent audits, and a strong free tier — the default recommendation when you need cloud sync outside Apple or Google.

  • Audited open-source clients
  • Excellent free plan and family tiers
  • Consistent experience across all major platforms
Learn more

LastPass

Caution

Legacy option — prefer Bitwarden for new users

Helped popularize cloud password managers, but high-profile incidents involving stolen encrypted vault backups pushed many security professionals toward Bitwarden or local KeePass for new deployments.

  • Usable with strong master password + MFA if already invested
  • Consider migrating if you are starting fresh
Learn more
Your priorityRecommendation
Live in Apple's ecosystemApple Passwords
Android & Chrome daily driverGoogle Password Manager
Maximum privacy and file controlKeePass (local vault)
Cross-platform cloud syncBitwarden
Existing LastPass userContinue if hardened; evaluate Bitwarden or KeePass

Sharing passwords securely

Even strong passwords sometimes need to be shared — with colleagues, family, IT admins, contractors, or clients. Too many people still send them through messaging platforms designed for chat, not secret delivery.

EmailSlackMicrosoft TeamsWhatsAppDiscordSMS
Use PrivateNote instead

PrivateNote encrypts secrets in your browser before upload. The server stores only ciphertext; the decryption key travels separately in the link. Notes can self-destruct after one read or expire on a schedule.

  • Passwords
  • API keys
  • Wi‑Fi credentials
  • Recovery codes
  • Temporary logins
Create a secure one-time note

Extra protection with password-protected notes

Add an optional password to a PrivateNote. The recipient needs both the link and the separate password — ideally delivered through different channels (email the link, share the password by phone or in person).

Even if someone intercepts the link, they cannot reveal the secret without the password.

Best practices

  • Use a long, unique master password
  • Enable multi-factor authentication on your password manager
  • Never reuse passwords across websites
  • Generate passwords with a password manager or Passwords.lu
  • Save every password in your encrypted vault
  • Enable passkeys whenever available
  • Regularly review password health reports
  • Share passwords through PrivateNote instead of email or chat
  • For highly sensitive credentials, use PrivateNote's optional password protection and deliver the password separately

Frequently asked questions

Are password managers safe?

Yes. Reputable password managers use strong, industry-standard encryption. For almost everyone, using a password manager is significantly safer than memorizing passwords or reusing the same password across multiple websites.

Can the password manager provider read my passwords?

For modern managers such as KeePass, Bitwarden, Apple Passwords, and Google Password Manager, your vault is encrypted before storage. Assuming you use a strong master password, the provider generally cannot read your stored credentials.

What happens if I forget my master password?

Most password managers cannot recover it because they never know it. This is deliberate. Some services offer recovery options or emergency access if configured ahead of time.

Should I use browser password storage?

Built-in Apple and Google managers are strong, stable choices within their ecosystems — backed by large security teams. KeePass suits maximum control. Bitwarden fits when you need cloud sync across mixed platforms, accepting higher server-side risk.

Final recommendation

No single manager is perfect for everyone — but using one is among the most effective steps you can take. Pair it with Passwords.lu for fast generation and PrivateNote when you need to share secrets securely.

  • Apple & Google — stable platform defaults
  • KeePass — local control, open source
  • Bitwarden — cloud sync when you need every device
  • Passwords.lu — fast browser-local generation

Explore other guides

Educational guide only. We may earn a commission from affiliate links when you use recommended services, which helps support this free privacy resource.