Password Managers: Setup, Migration & Features
Picking a password manager is just the start. This guide covers secure migration, browser integration, emergency access, and advanced vault security features.
Table of Contents
- Why a Password Manager Is Non-Negotiable
- Choosing a Password Manager
- Setting Up for the First Time
- Migrating Existing Passwords
- Importing from Your Browser
- Dealing with Weak and Duplicate Passwords
- Advanced Features Worth Using
- TOTP (Two-Factor) Storage
- Secure Notes and Document Storage
- Sharing and Emergency Access
- Master Password Best Practices
- Security Model Limitations
Why a Password Manager Is Non-Negotiable
The average person has over 100 online accounts. The only secure approach is a unique, strong, random password for every single one. No human brain can manage that — which is exactly why password managers exist.
A password manager encrypts and stores all your credentials in a vault protected by a single strong master password. It auto-fills credentials, generates secure passwords, and often syncs across devices. The security model is sound: even if the company's servers are breached, your vault is encrypted with your master password, which they never see.
Choosing a Password Manager
The top contenders for most users:
Bitwarden — Open source, audited, free tier that covers most needs, paid tier adds TOTP and Bitwarden Authenticator. Self-hosting is possible. Best choice for privacy-conscious users who want full transparency.
1Password — Polished UI, excellent family and team plans, travel mode feature, built-in TOTP authenticator. Proprietary but well-audited. 14-day trial, then paid.
Proton Pass — From the makers of ProtonMail. Strong privacy stance, E2EE including metadata. Integrated with Proton ecosystem.
Apple Passwords / iCloud Keychain — Seamless for Apple-only users, now a standalone app in iOS 18 and macOS 15. Free but limited cross-platform support.
Avoid: Browser-built-in password managers (Chrome, Firefox) for serious use — they lack advanced features, vault export controls, and dedicated security audits.
Setting Up for the First Time
- Choose your manager and create an account.
- Generate your master password: Use a passphrase of 4–6 random words (e.g., "staple-umbrella-river-fog-2024"). This is the one password you must memorize — make it strong but memorable. Write it on paper and store it somewhere physically secure.
- Install the browser extension: This is what enables auto-fill and password capture as you log in to sites.
- Install the mobile app: Enable biometric unlock (Face ID or fingerprint) for convenience — this unlocks the vault without re-entering the master password each time.
- Set a vault timeout: Configure the vault to lock after 15 minutes of inactivity, or when the browser closes.
Migrating Existing Passwords
This is where most people get stuck. Here's a systematic approach:
Importing from Your Browser
Chrome, Firefox, Edge, and Safari all allow you to export saved passwords as a CSV file. Steps:
- In Chrome: go to
chrome://password-manager/settingsand export - In Firefox: go to Settings > Privacy & Security > Saved Logins > Export
- Import the CSV into your password manager using its built-in import tool
- After successful import, delete the CSV file immediately — it's plaintext
Dealing with Weak and Duplicate Passwords
After import, your password manager will flag weak, reused, and compromised passwords. Prioritize fixing:
- Email accounts first — email is the master key to all other accounts
- Financial accounts — banking, credit cards, investment platforms
- **Any account linked to your primary email or phone
- Everything else, working down the security priority list
Go to each flagged site, use your manager's built-in password generator to create a new strong password (at least 16 characters, random), update it on the site, and save it. Most managers offer a one-click password-change flow.
Advanced Features Worth Using
TOTP (Two-Factor) Storage
Bitwarden and 1Password can store TOTP secrets alongside passwords, meaning the manager generates your 2FA codes too. This is convenient but creates a single point of failure — if your vault is compromised, both factors are exposed. For highest-value accounts, keep TOTP in a separate dedicated authenticator app (Aegis on Android, Raivo on iOS).
Secure Notes and Document Storage
Password managers can store more than passwords:
- Wi-Fi network credentials
- Software license keys
- Recovery codes for 2FA
- Passport and identity document details (for autofill on travel booking sites)
- Secure notes with sensitive information
Sharing and Emergency Access
1Password's family plan and Bitwarden's organization feature let you share specific vault items with trusted people — useful for shared accounts and family credentials.
Bitwarden offers Emergency Access: designate a trusted contact who can request vault access after a waiting period you define (e.g., 7 days). This solves the "what happens if I'm incapacitated" problem.
Master Password Best Practices
- Never store the master password digitally without its own separate encryption layer
- Write it on paper and store in a fireproof location or safety deposit box
- Set up emergency access before you need it
- Enable two-factor authentication on your password manager account itself — this is critical
- Set up account recovery options offered by your provider
Security Model Limitations
Password managers are excellent tools with real limitations to understand:
- Master password compromise renders everything vulnerable — protect it accordingly
- Malware on your device can capture auto-filled passwords at the point of entry
- Phishing sites — your manager may refuse to auto-fill on a fake site that doesn't match the saved domain, which is actually a useful anti-phishing feature
- Cloud sync means your encrypted vault is on someone's servers — self-hosting (Bitwarden) eliminates this concern
A password manager is the single highest-leverage security improvement most people can make.