LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Tutorials
Intermediate 13 min read

Password Managers: Setup, Migration & Features

Picking a password manager is just the start. This guide covers secure migration, browser integration, emergency access, and advanced vault security features.

15 September 2026

Why a Password Manager Is Non-Negotiable

The average person has over 100 online accounts. The only secure approach is a unique, strong, random password for every single one. No human brain can manage that — which is exactly why password managers exist.

A password manager encrypts and stores all your credentials in a vault protected by a single strong master password. It auto-fills credentials, generates secure passwords, and often syncs across devices. The security model is sound: even if the company's servers are breached, your vault is encrypted with your master password, which they never see.

Choosing a Password Manager

The top contenders for most users:

Bitwarden — Open source, audited, free tier that covers most needs, paid tier adds TOTP and Bitwarden Authenticator. Self-hosting is possible. Best choice for privacy-conscious users who want full transparency.

1Password — Polished UI, excellent family and team plans, travel mode feature, built-in TOTP authenticator. Proprietary but well-audited. 14-day trial, then paid.

Proton Pass — From the makers of ProtonMail. Strong privacy stance, E2EE including metadata. Integrated with Proton ecosystem.

Apple Passwords / iCloud Keychain — Seamless for Apple-only users, now a standalone app in iOS 18 and macOS 15. Free but limited cross-platform support.

Avoid: Browser-built-in password managers (Chrome, Firefox) for serious use — they lack advanced features, vault export controls, and dedicated security audits.

Setting Up for the First Time

  1. Choose your manager and create an account.
  2. Generate your master password: Use a passphrase of 4–6 random words (e.g., "staple-umbrella-river-fog-2024"). This is the one password you must memorize — make it strong but memorable. Write it on paper and store it somewhere physically secure.
  3. Install the browser extension: This is what enables auto-fill and password capture as you log in to sites.
  4. Install the mobile app: Enable biometric unlock (Face ID or fingerprint) for convenience — this unlocks the vault without re-entering the master password each time.
  5. Set a vault timeout: Configure the vault to lock after 15 minutes of inactivity, or when the browser closes.

Migrating Existing Passwords

This is where most people get stuck. Here's a systematic approach:

Importing from Your Browser

Chrome, Firefox, Edge, and Safari all allow you to export saved passwords as a CSV file. Steps:

  • In Chrome: go to chrome://password-manager/settings and export
  • In Firefox: go to Settings > Privacy & Security > Saved Logins > Export
  • Import the CSV into your password manager using its built-in import tool
  • After successful import, delete the CSV file immediately — it's plaintext

Dealing with Weak and Duplicate Passwords

After import, your password manager will flag weak, reused, and compromised passwords. Prioritize fixing:

  1. Email accounts first — email is the master key to all other accounts
  2. Financial accounts — banking, credit cards, investment platforms
  3. **Any account linked to your primary email or phone
  4. Everything else, working down the security priority list

Go to each flagged site, use your manager's built-in password generator to create a new strong password (at least 16 characters, random), update it on the site, and save it. Most managers offer a one-click password-change flow.

Advanced Features Worth Using

TOTP (Two-Factor) Storage

Bitwarden and 1Password can store TOTP secrets alongside passwords, meaning the manager generates your 2FA codes too. This is convenient but creates a single point of failure — if your vault is compromised, both factors are exposed. For highest-value accounts, keep TOTP in a separate dedicated authenticator app (Aegis on Android, Raivo on iOS).

Secure Notes and Document Storage

Password managers can store more than passwords:

  • Wi-Fi network credentials
  • Software license keys
  • Recovery codes for 2FA
  • Passport and identity document details (for autofill on travel booking sites)
  • Secure notes with sensitive information

Sharing and Emergency Access

1Password's family plan and Bitwarden's organization feature let you share specific vault items with trusted people — useful for shared accounts and family credentials.

Bitwarden offers Emergency Access: designate a trusted contact who can request vault access after a waiting period you define (e.g., 7 days). This solves the "what happens if I'm incapacitated" problem.

Master Password Best Practices

  • Never store the master password digitally without its own separate encryption layer
  • Write it on paper and store in a fireproof location or safety deposit box
  • Set up emergency access before you need it
  • Enable two-factor authentication on your password manager account itself — this is critical
  • Set up account recovery options offered by your provider

Security Model Limitations

Password managers are excellent tools with real limitations to understand:

  • Master password compromise renders everything vulnerable — protect it accordingly
  • Malware on your device can capture auto-filled passwords at the point of entry
  • Phishing sites — your manager may refuse to auto-fill on a fake site that doesn't match the saved domain, which is actually a useful anti-phishing feature
  • Cloud sync means your encrypted vault is on someone's servers — self-hosting (Bitwarden) eliminates this concern

A password manager is the single highest-leverage security improvement most people can make.

#password manager#Bitwarden#1Password#passwords