BloomerBoomer

Life, money and technology after 55

Technology

Technology

Password Managers: Less Work Than What You Do Now

Two objections come up every time, and both are reasonable on the surface.

It sounds complicated. It is less work than what you are doing now, after one evening of setup.

For a practical workplace perspective, Monitask explains workforce analytics software and how it is used.

Putting everything in one place sounds risky. It is considerably safer than the alternatives, and the reason is worth understanding rather than taking on trust.

The actual problem it solves

Nobody remembers forty distinct strong passwords. So people do one of three things:

Use the same password everywhere. When any one of those services is breached — and they are, routinely — the attackers have your email and password. They then try that combination everywhere else. This is the single most common way ordinary accounts are taken over, and it has a name: credential stuffing. It requires no skill and it is automated.

Use small variations. Sailing2019, Sailing2020. Trivially handled by the same automated tools.

Write them in a notebook. Actually better than the first two — a burglar is a far less likely threat than an automated database attack. It fails on convenience and on the fact that you cannot generate strong passwords by hand.

A manager means every account has a different long random password, and you never see or type any of them.

Why one place is safer, not riskier

The instinct — all eggs in one basket — assumes the basket is as weak as the alternatives. It is not.

The contents are encrypted with your master password, and reputable providers cannot read them. When one of these companies has been breached, the stolen data was encrypted and largely useless.

Compare it with the actual alternative. Your current situation is one password protecting dozens of accounts, held by dozens of companies with wildly varying security, at least one of which will be breached. That is the risky arrangement, and it is the one most people are in.

The one thing that matters is the master password, and it is the only one you need to remember.

Choosing a master password

Not a word with numbers on the end.

Use four or five unrelated words. Something like harbour-pencil-thunder-marmalade. Long, memorable, and far stronger than P@ssw0rd2026.

Do not reuse it anywhere. This is the one password that must be unique.

Write it down once and store it securely — with your will, in a safe, with the person who handles your affairs. This is not bad practice; the realistic risk is you losing access, not a burglar finding it. See what happens to your accounts.

Turn on two-factor authentication for the manager itself. See two-factor authentication.

What using it is actually like

Better than what you do now, which is the part people do not expect.

Signing in: the app fills in the details. You do not type anything.

A new account: it offers to generate a password and saves it.

A password change: it notices and offers to update.

On your phone: unlocks with your fingerprint or face.

Shopping: it fills in card details and addresses too.

No more forgotten passwords, no more reset emails, no more trying four variations. That is the daily experience, and it is the reason people who adopt one rarely go back.

Which one

The one built into your phone or browser is a legitimate choice and much better than nothing. Apple's Passwords app and Google's password manager both work well and cost nothing. The limitation is moving between systems — an Apple one is awkward on a Windows computer.

A dedicated manager works everywhere and offers family sharing and emergency access. Several reputable options exist at modest annual cost, and free tiers are usually sufficient for one person.

We do not recommend specific products, and you should be sceptical of sites that do — this category is heavily monetised through affiliate commissions.

What to look for: independent security audits published publicly, a clear statement that the company cannot read your data, works on all the devices you use, and an emergency access feature.

Getting started without doing everything

The mistake is trying to convert forty accounts in one sitting. Nobody finishes.

Install it and set the master password.

Add accounts as you use them. Over a month, everything you actually use ends up in it, and the things you never use were not worth the effort.

Do the important ones deliberately, first: email, bank, and anything holding payment details. Change those to new generated passwords rather than importing the old ones.

Your email is the most important account you own — whoever controls it can reset everything else. Give it a strong unique password and two-factor authentication before anything else.

Then check for leaks. Most managers will tell you which of your saved passwords have appeared in known breaches. It is usually a longer list than expected, and it gives you an order to work through.

If you would rather not

A notebook is a legitimate fallback, and it is better than one password everywhere.

If you use one: keep it somewhere secure rather than beside the computer, do not label it, and still make the email password unique and strong.

And still turn on two-factor authentication on email and banking. That single step protects you even if a password leaks.

The evening's work

  • [ ] Install a manager and set a four-word master password
  • [ ] Write the master password down and store it securely
  • [ ] Turn on two-factor authentication for the manager
  • [ ] Change your email password to a generated one
  • [ ] Change your bank password
  • [ ] Add everything else gradually, as you go

Two accounts done properly on the first evening is a successful first evening.

For additional public information on consumer fraud and scam prevention, see Federal Trade Commission.