Every browser now offers to remember your passwords, and your phone does too. So it is fair to ask whether paying for a separate password manager is worth it. For some people the built-in option is enough. For most households and nearly every small business, it is not, and the reasons are practical rather than technical.
First, what both of them fix
The biggest risk with passwords is reuse. When one website is broken into, criminals try the stolen email and password combinations on banks, email providers and shops. If you use one password in several places, one break-in opens them all.
Any password manager, built-in or separate, fixes this the same way: it makes up a long random password for every account and remembers it for you. If the choice is between your browser's manager and reusing passwords, use the browser's manager today. It is a big step up.
Where the built-in managers fall short
They are tied to one company's world. Passwords saved in Safari live most comfortably on Apple devices. Chrome's live in your Google account, and Edge's in your Microsoft account. A household with an iPhone, a Windows laptop and an Android tablet ends up with passwords scattered across three systems, and none of them has the full set.
Sharing is limited. Families and offices share more sign-ins than they realize: streaming services, the utility company, the school portal, the Wi-Fi, the company's supplier accounts. Built-in managers have added some sharing, but mostly between people who use the same brand of device. The usual result is passwords sent by text message, which is exactly what you want to avoid.
They only hold passwords. A dedicated manager is also a safe place for the things people keep in a notes app or a desk drawer: passport and driving licence numbers, software licence keys, the alarm code, the answers to security questions, the recovery codes for two-step sign-in.
They are only as locked as the device. On many computers, anyone who can use your unlocked browser can view every saved password. A dedicated manager locks separately and asks again after a period of time.
There is no plan for emergencies. If you are in hospital, who can pay the bills? A good password manager gives a family a proper way to recover access. A browser does not.
What a dedicated manager adds
- It works the same on every device and in every browser, whichever brands you own.
- Shared vaults, so a couple, a family or a team see the same up-to-date sign-ins without ever sending one in a message.
- Warnings about passwords that are weak, reused or known to have been stolen in a break-in.
- Secure notes, documents and card details beside the passwords.
- Support for passkeys, the newer sign-in method that is replacing passwords on many sites.
- For a business: each person's access can be given and taken away, which matters on the day someone leaves.
Which one we use
We use 1Password, and it is the one we suggest to families and small offices. The reasons are ordinary ones. It works on everything, including Linux. Its Watchtower feature lists the passwords you should change first, which makes the clean-up manageable. The family plan gives each person a private vault as well as shared ones, and lets a family organizer help someone who is locked out. There are business plans for a team.
It is not the only good choice. Whatever you pick, look for these: it works on all the devices you own, it has been independently security tested, it supports two-step sign-in on the manager itself, and it lets you export your data if you ever want to leave.
Who can stay with the browser
If you live alone, use one brand of device for everything, share no accounts with anyone, and your device locks itself with a good passcode, the built-in manager is a reasonable choice. Turn on two-step sign-in for the account behind it, because that account now protects everything.
Is it safe to put everything in one place?
It is a sensible worry. The answer is that a good manager encrypts your data on your own device before it goes anywhere, with a key that comes from your master password. The company cannot read it, and neither can anyone who breaks into the company. The realistic danger to most people is not a vault being cracked. It is the same weak password used on forty websites.
Protect the vault properly and it is far safer than any alternative: a long master password made of several words, two-step sign-in turned on, and the recovery details printed and kept somewhere safe at home.
Getting started without it becoming a project
- Install the manager on your phone and your main computer.
- Add your email and your bank first, and change both to new, generated passwords.
- Let it save the rest as you sign in to things over the coming weeks.
- After a month, look at its list of weak and reused passwords and fix the important ones.