Why using a password manager is Important!
The case for a password manager, and the one technical detail that separates the ones that survived a breach from the one that didn't , it isn't the encryption cipher.
It still surprises me how many people have never used a password manager, and are fine with that.
I came to them the boring way. My online presence got disorganised. I had something like a thousand accounts, and remembering which email address I signed up with was already a nightmare before we even get to the passwords. Some platforms demand long, complex, rotating credentials, and they're right to. Trying to hold all of that in my head was exhausting, so I went looking for a way not to.
Password managers aren't new. What people miss is why they work. So let's break it down.
What Is a Password Manager?
A password manager generates random passwords for the sites you use, stores them in an encrypted vault, and fills them in for you. Most will also fill your name, address and card details into forms, and many will store things that aren't passwords at all, recovery codes, licence keys, passport numbers, safe combinations.
The good ones do something more useful than storage: they tell you which of your existing passwords are weak, reused, or already sitting in a breach dump, and they push you toward a unique credential per account. Set the generator to at least 20 characters with the full character set and stop thinking about it.
That last point is the whole argument. The value isn't convenience, it's that you stop reusing passwords, and reuse is what turns one breach into thirty.
The Risks of Using a Password Manager
There's no way to be completely safe online, and a password manager is no exception. The usual objection is the eggs-in-one-basket one, and it's fair: your vault holds everything, so it's a single target.
That objection is real but it's aimed at the wrong layer. The thing that actually protects you is that the vault is encrypted on your device before it goes anywhere, and the provider never has the key. If their servers are breached (and with some providers they have been) what the attacker gets is ciphertext.
The genuine risk is different, and it's worth being precise about: malware on your own device. If something is logging your keystrokes when you unlock your vault, encryption is irrelevant. It doesn't matter how good the vault is if someone is watching you open it. That's why securing the devices you use matters more than agonising over which provider has the nicer audit report.
Is a Password Manager Safe?
Yes, and the reason is narrower than most articles admit.
Most guides stop at "they use AES-256, which is military-grade." Two problems with that. AES-256 isn't "military-grade", it's the ordinary, correct choice for symmetric encryption, and every serious password manager uses it. It's also not the part that breaks.
The cipher has never been the weak link. The key derivation function is.
Your master password isn't used directly as an encryption key. It's stretched into one through a key derivation function, and how hard that stretching is decides how expensive it is for an attacker to guess your master password offline, once they have a copy of your encrypted vault. This is the number that matters, and it's the one most comparisons omit.
The worked example is LastPass. In the 2022 breach, vaults were exfiltrated. Legacy accounts were using PBKDF2 with only 5,000 iterations. At that setting, a single consumer GPU (one RTX 4090) can attempt roughly 1.5 million master password guesses per second. Documented theft from those vaults ran to more than $35 million in cryptocurrency. Nothing was wrong with their AES. The stretching was too cheap.
Compare the current field:
- 1Password. AES-256-GCM, PBKDF2-HMAC-SHA256 at roughly 650,000 iterations, plus a 128-bit Secret Key generated on your device and combined into the derivation. The Secret Key never leaves your hardware, which makes offline brute-forcing impractical even against a weak master password.
- Bitwarden. AES-256-CBC with HMAC-SHA256, PBKDF2-SHA256 at 600,000 iterations, with Argon2id as the default for newer accounts. Argon2id is memory-hard: at 64MB it drops the GPU attack rate to around 500 guesses per second, because the memory requirement defeats the parallelisation GPUs depend on.
The OWASP Password Storage Cheat Sheet recommends Argon2id first, and PBKDF2-SHA256 with a minimum of 600,000 iterations where Argon2id isn't available, usually for FIPS compliance.
So when you're evaluating a manager, the question isn't "does it use AES-256." They all do. It's: which KDF, at what parameters, and can you raise them yourself?
Beyond that, the safety properties that matter:
- Zero-knowledge architecture. Your vault is encrypted on your device. The provider stores ciphertext and has no way to decrypt it. This is why a breach of their servers is survivable.
- A strong master password. It's the one password you actually have to remember, and it's the input to the KDF, so its strength directly sets the cost of an offline attack. Length beats complexity: a long passphrase you can remember is better than eight characters of punctuation soup.
- Two-factor authentication on the account itself. This doesn't protect the vault's encryption, but it stops someone who has your master password from logging in and pulling a copy in the first place.
- Independent audits. Bitwarden has been through repeated Cure53 assessments covering clients, server infrastructure and cryptographic implementation, plus a 2025 cryptography review with ETH Zurich. 1Password holds SOC 2 Type 2. A manager that has never been independently audited is asking you to take its word for it.
If you want the practical version of this (running the reports, checking your KDF settings, fixing what you find) that's how to audit your password manager.
Which Type Is Most Secure?
Password managers fall into three broad categories, with different trade-offs.
Browser-based. Built into Chrome, Firefox, Safari and Edge. Convenient, and better than nothing. I don't recommend them as your primary vault, for reasons in the next section.
Cloud-based. The common case. Bitwarden, 1Password, Dashlane and similar. Encrypted on your device, synced through the provider's servers. They handle backups, cross-device sync, secure notes, card details, breach monitoring and password generation. The trade-off is that you're trusting their implementation of zero-knowledge, which is why audits and open source matter here more than anywhere else.
Local or desktop-based. KeePassXC is the reference implementation. Your database is a file on your own disk; nothing syncs anywhere unless you arrange it. That removes the provider from your threat model entirely, and adds you to it. You own the backups, and losing the file loses the vault. The realistic attack is still malware or a keylogger capturing your master password.
There's a fourth position worth knowing about: stateless generators like LessPass, which derive each site's password from a master password, the site name and a counter, and store nothing at all. There's no vault to steal because there's no vault. The trade-off is real though, rotate the master password and every derived password changes, and you lose the ability to store anything that isn't a password.
Why Browser-Based Password Managers Aren't Ideal
It comes down to focus.
A browser vendor's priority is the browser. The password manager is a feature they maintain, not a product they compete on, and it shows. Historically they've been slow to add strong generation, they tie you to one ecosystem, and the vault lives inside the same application that renders untrusted web content all day.
Dedicated managers have spent years adding exactly the things a browser never gets to: sharing, emergency access, breach monitoring, KDF tuning, hardware key support, CLI and SSH agent integration, and self-hosting if you want it.
That's not a claim that browsers are unsafe. It's that the security work in this space is done by people whose entire job is this one thing.
What If Your Password Manager Gets Hacked?
This is where the distinction matters, and it's the question that decides whether you should trust any of this.
A provider being breached is not the same as your vault being compromised. Those get reported as if they're the same event. They aren't. Because the vault is encrypted before it leaves your device, a server breach usually yields ciphertext, and ciphertext is only as exposed as the KDF is cheap.
Which is exactly why LastPass went badly and the others haven't. Exfiltrated vaults with 5,000-iteration PBKDF2 were crackable. The same breach against Argon2id vaults would have produced a lot of expensive noise.
So the honest answer to "what if it gets hacked" is:
- If your master password is strong and the KDF is properly tuned, an exfiltrated vault is a problem you have time to respond to, not an instant total loss.
- If your master password is weak, or the provider left the KDF at a legacy setting, it's a genuine emergency.
- If the attacker has malware on your device, none of the above applies. They don't need to crack anything.
I'd stop short of saying the odds of a successful attack are zero. Biometrics and hardware keys raise the bar a great deal, but "zero" isn't a word that belongs in this paragraph. What's true is that social engineering and phishing are far cheaper attacks than cracking a well-derived vault, so that's where the effort actually goes.
Why Would I Pick a Premium Password Manager?
Not for the encryption. Both free and paid managers use AES-256 and zero-knowledge design, and the good free tiers are genuinely good.
Pay for the operational extras: emergency access so someone can reach your vault if you're incapacitated, hardware key support, larger encrypted file storage, integrated TOTP, sharing and collections for a household, and audit reporting. Those are the things that separate a vault from a system.
The honest framing is that the free tier of a reputable manager beats the paid tier of an unreputable one. There are excellent free options, and there are cheap managers built by companies you've never heard of with no audit history and no source to inspect. Price isn't the signal. Provenance is.
So, Which Is the Best Password Manager?
This is where reasonable professionals disagree, because it depends on what you're optimising for. For me it's security and privacy, which is why open source carries a lot of weight. I can have someone else's work checked rather than taking a vendor's word for it.
With that bias stated, these are the ones I'd put in front of someone:
- Bitwarden, the default recommendation. Open source across client and server, repeatedly audited by Cure53, cross-platform, self-hostable if you want to remove the provider entirely, and free for personal use with unlimited devices and sync. The Premium tier is $19.80/year after Bitwarden's January 2026 price increase (its first in a decade) and the free tier is genuinely enough for most people.
- LessPass, for people who want no storage and no sync at all. Passwords are derived, not saved. Read the trade-off above before committing to it.
- KeePassXC, the local-first option. Industry-standard encryption in a file you own, desktop auto-type, browser extension, and KeePassDX on Android from Google Play or F-Droid. Best when you'd rather own the operational burden than delegate it.
If you're starting from nothing, this comparison of the main providers covers pricing, audits and architecture side by side, and how to set up Bitwarden walks the setup end to end.
Why Not the Rest?
Fair question, since LastPass and 1Password are the two names people expect to see.
LastPass is excluded on the evidence. The 2022 breach produced real, documented losses because of a legacy KDF configuration, and the handling of it did lasting damage to trust. That isn't a grudge; it's the single most instructive failure in this space, and it's why key derivation gets its own section above.
1Password is a different case, and I want to be accurate about it. It isn't excluded for being insecure, it's arguably the strongest architecture here, between the Secret Key and a very high iteration count. It's excluded because it's closed source, and for my own use I weight inspectability heavily. That's a preference, not a finding. If you'd rather have the polished product than the inspectable one, 1Password is a defensible choice and you won't be less safe for it.
Password Managers for Business Use
Business is a different problem, because the hard part isn't encryption, it's provisioning, offboarding and least privilege.
The core is a shared organisation vault with roles: admins control who can see which collections, and when someone leaves you revoke one account instead of chasing a spreadsheet of shared credentials. Look for SSO integration, directory sync (SCIM) so joiners and leavers are handled automatically, role-based access control, and audit logging that tells you who accessed what.
One clarification, because it gets muddled: SSO and password managers solve different problems. SSO reduces the number of credentials by federating identity to a provider. It's excellent where it applies, but plenty of services still have no SSO option, and something has to hold those credentials. That's the password manager's job. Most organisations end up running both, and the password manager is what covers the gap SSO leaves.
If you're evaluating for a team, Bitwarden's Teams and Enterprise tiers and 1Password Business both cover the requirements above; the comparison page has the pricing side by side.
Thanks for reading, and if you haven't run a breach report on your own vault yet, that's a better use of the next ten minutes than picking a new provider.