How to Choose a Password Manager
Nearly every password manager on the market covers the basics well. The differences that actually matter are underneath the surface — the encryption model, what happens if the company itself is breached, and how well it fits into your actual daily workflow. Here's what to check.
1. Zero-knowledge encryption, confirmed
This is non-negotiable. Look for explicit confirmation that encryption and decryption happen locally on your device, and that the provider never has access to your master password or the decryption key. This is usually described as "zero-knowledge" architecture in the provider's security documentation — if you can't find a clear explanation of this, that's a red flag, not an oversight.
2. Independent security audits
Reputable password managers commission regular third-party security audits and publish the results, or at least a summary. A provider that's never been independently audited is asking you to trust their own marketing claims about their own security — which is exactly the situation a password manager is supposed to remove.
3. Cross-platform support that actually matches your life
Check that it works properly across every device and browser you actually use, not just the ones featured on the homepage. A manager that's excellent on desktop but clunky on mobile will quietly train you to skip it under time pressure — which defeats the purpose.
4. Built-in generator and breach monitoring
A good manager doesn't just store passwords you already have — it should generate new, high-entropy ones on the spot, and flag weak or reused passwords in your existing vault automatically. Breach monitoring, which checks your saved credentials against known breach databases and alerts you if one shows up, is increasingly a standard feature and worth prioritising.
5. A sane recovery process
Ask what happens if you forget your master password. Some providers offer account recovery through secondary verification; others are strictly zero-knowledge and cannot recover your vault under any circumstances if you lose the master password, by design. Neither answer is wrong, but you should know which trade-off you're accepting before you commit, not after you're locked out.
6. Free vs paid, realistically
Most reputable providers offer a genuinely usable free tier covering unlimited passwords and basic sync. Paid tiers typically add features like secure file storage, family sharing, or advanced breach monitoring. For most individuals, the free tier of a reputable provider is a dramatic upgrade over no password manager at all — don't let a subscription decision delay getting started.
What to ignore
Flashy interface design and celebrity endorsements say nothing about the underlying security model. Focus on the encryption architecture, audit history and platform coverage — everything else is preference.
Put this into practice right now.
Generate a strong password →