We're going to try to convince you to install a password manager. It is the single least glamorous piece of software we could possibly recommend. It will not do anything cool. Nobody will notice you use one. And if you set it up this weekend, it is the biggest security upgrade you'll make this decade.
Here's the case, briefly, followed by the exact setup.
Why this matters more than antivirus
The average American has 130-something online accounts. Nobody remembers 130 unique passwords. So most people reuse — often the same password across five or six sites. That's the whole problem.
Every year, dozens of companies get their user databases stolen. If any one of them was where you used your "main" password, criminals now have your email and that password. Their next move is to try logging into your bank, Amazon, PayPal, and email with the exact same combination. This is called credential stuffing, and it is by far the number one way regular people get their accounts broken into. Not fancy hacking. Just password reuse.
Which one to use
Any of these three. Pick one and move on with your life:
- Bitwarden — Free forever for personal use, open source, works on everything. What we personally use. Slightly less polished than the paid options but genuinely fine.
- 1Password — $3/month. The most polished experience. Family plan is $5/month for up to 5 people, which is what we recommend to households.
- Apple Passwords (built into iOS/macOS) — Free and now genuinely good if your whole family is on Apple. Skip it if anyone uses Windows or Android.
Whichever you pick will be dramatically better than what you're doing now. Do not agonize over the choice. Pick one in the next 60 seconds.
The 20-minute setup
1. Install it on your primary computer and phone
Download from the actual app store or the actual website — not a link in an email, and not the first Google result (some fake versions have shown up). Type the URL yourself: bitwarden.com or 1password.com.
2. Create one really good master password
This is the last password you'll ever memorize. Make it good. Our recommendation: four random words with a number and symbol thrown in. Something like parachute-brie-lantern-echo-42! Real length, easy to type, impossible to guess. Write it down on paper and keep it somewhere physically safe. Yes, on paper. Yes, really.
3. Turn on two-factor for the password manager itself
Every good password manager supports this. Do it during setup. The most common option is a code from an authenticator app on your phone. This means even if someone got your master password, they'd also need your phone. Big deal.
4. Import from your browser
Chrome, Edge, and Safari all have "export passwords" built into their settings. Every password manager has "import passwords." Do this once. You'll immediately have 50+ passwords in your vault. Delete them from the browser after.
5. Turn off password saving in your browser
You want one system, not two. In Chrome/Edge settings, disable "Offer to save passwords." From now on, your password manager fills things in. Your browser stops trying to.
6. As you use the internet this week, let it help
Any time you log in somewhere, the password manager will offer to save that entry. Say yes. Within two weeks it will have everything important. Don't try to do it all in one sitting — you'll get bored and quit.
The five accounts to change the password on first
You don't have to change every password immediately. Do these five this weekend and you've closed 80% of the risk:
- Your primary email. Everything else can be reset through this — so it's the crown jewels.
- Your bank(s). Obvious.
- Amazon. Has your card on file and can ship to any address.
- Your work email or work login (if you have one).
- Any account tied to your Social Security number — IRS, tax software, health insurance portal, retirement account.
For each, log in, go to settings, generate a new password with the password manager (it'll suggest a 20-character random one), save it, and enable two-factor authentication while you're there. Ten minutes each.
The last thing: why this makes you boring to criminals
Criminals are essentially running a business. They target the easiest 10% of people because that's where the ROI is. When your passwords are unique, long, and locked behind a master + a second factor, breaking into your account isn't difficult — it's economically pointless. They will move on to someone easier.
That is genuinely the entire strategy. Not "make yourself unhackable." Just "make yourself not-worth-hacking." A password manager does that in one weekend.