Price captures verified 2026-08-09; overall scores unpublished
How Password Managers Work
Vault, then autofill: a password manager keeps unique site passwords in an encrypted vault you unlock with a master password (plus MFA), then offers those secrets through official apps and extensions. It does not make phishing or malware disappear, and vendor zero-knowledge claims stay claims until you read primary sources. Stop reuse and turn on MFA for email first. Optional paid cards use claim-ledger prices from 2026-08-09 (NordPass Premium from $1.39/mo on a 2-year USD plan; 1Password Individual $2.99/mo billed annually; Bitwarden Premium $1.65/mo billed annually for comparison-only diligence). Overall scores stay unpublished. Who should not buy: anyone who skipped free hygiene, or who needs a published lab score before deciding.
- Guide · Educational · ~12 min read
Direct definition
A password manager is software that stores login credentials in an encrypted vault unlocked by a master password (and usually MFA), then fills unique site passwords through official apps or browser extensions so you do not reuse the same secret across services.
Key takeaways
- 1Read the vault model below so you know what you are buying
- 2Create a long unique master password you will not reuse elsewhere
- 3Stop new password reuse today (browser generator is fine as a bridge)
- 4Enable MFA on email and on any vault you install
- 5Practice unlock and autofill on two low-risk sites before banking
- 6Open the Password Manager Finder only if sync or sharing still hurts
How it works
- 1Free
The vault model in plain language
Your vault holds logins, notes, and sometimes passkeys. A master password unlocks ciphertext on your devices according to the vendor’s model. Marketing that says the vendor “cannot see your passwords” is a claim to verify on trust/security pages, not a guarantee we invent here.
- One vault account, not three half-used apps
- Memorize a long unique master password
- Enable MFA on the vault itself
- 2Free
Autofill and password generators
Official extensions and apps detect login forms and can generate long random passwords per site. Autofill is a convenience layer; if a site breaks autofill, copy from the vault carefully. Never install lookalike extensions from ads.
- Install only from official vendor pages or app stores
- Generate a unique password when changing a reused one
- Avoid saving banking secrets in plain notes apps
- 3Free
Sync, devices, and recovery
Cloud sync keeps phones and laptops aligned and creates recovery and device-list responsibilities. Review trusted devices, remove old phones, and practice recovery before an emergency. A vault nobody can recover is a household risk.
- Review the trusted-device list monthly at first
- Store recovery codes offline (not in the vault alone)
- Keep apps updated from official channels
- 4Free
What a manager does not do
It does not replace MFA, antivirus hygiene, or phishing caution. It does not prove a vendor is breach-proof. It will not fix accounts you still share in chat. Treat “unlimited devices” and similar slogans as plan marketing until you confirm current plan cards.
- MFA on email remains mandatory
- Bookmark real unlock URLs; beware lookalikes
- Share only through vault features, never SMS passwords
- 5Optional paid
When a paid product is justified
Pay when browser storage cannot cover cross-browser sync, intentional sharing, or recovery you trust. NordPass fits a simpler personal upgrade (Premium from $1.39/mo on a 2-year USD plan, 2026-08-09). 1Password fits structured sharing (Individual $2.99/mo billed annually the same day). Bitwarden remains useful free/open-source research at Premium $1.65/mo billed annually (comparison-only, no /go/ deal).
- Confirm the job is sync/sharing, not one reused email password
- Read who should not buy on product pages
- Use /go/ only for pack merchants you choose
Limits of this explainer
- The need to trust official apps and keep them updated
- Sites with broken autofill that still need careful manual entry
- Recovery processes you must practice before an emergency
- Phishing that captures a master password on a fake unlock page
- Invented encryption grades or unpublished audit scores
Sources
- Security Checklist methodology, Educational guides stay free-first; scores unpublished until test records exist
- NordPass claim ledger, data/claim-ledgers/nordpass.json#nordpass-starting-price; Premium from $1.39/mo (2-year USD via NordSec GraphQL) captured 2026-08-09
- 1Password claim ledger, data/claim-ledgers/1password.json#1password-starting-price; Individual $2.99/mo billed annually captured 2026-08-09
- Bitwarden claim ledger, data/claim-ledgers/bitwarden.json#bitwarden-starting-price; Premium $1.65/mo billed annually; comparison-only (2026-08-09)
- Claim ledgers (T014), nordpass.json, 1password.json, bitwarden.json, dashlane.json: starting prices verified 2026-08-09; scores unpublished
- Vendor marketing pages, Feature and architecture claims from official sites, not independent lab evidence; re-verify same-day before purchase advice
- Security Checklist methodology, How password-manager reviews are structured before scores publish, /methodology/
Frequently asked questions
Internal links
Continue in this cluster
Hub, tools, and related pages from the inventory. No invented URLs.
Expert guides & insights
Related guides
Stay in the same problem space without jumping brands.
Want launch updates?
The email newsletter is not running yet. Use Contact if you want a human reply when it opens. No fake signup form.
