We're going to try to convince you to install a password manager. It is the single least glamorous piece of software we could possibly recommend. It will not do anything cool. Nobody will notice you use one. And if you set it up this weekend, it is the biggest security upgrade you'll make this decade.

Here's the case, briefly, followed by the exact setup.

Why this matters more than antivirus

The average American has 130-something online accounts. Nobody remembers 130 unique passwords. So most people reuse — often the same password across five or six sites. That's the whole problem.

Every year, dozens of companies get their user databases stolen. If any one of them was where you used your "main" password, criminals now have your email and that password. Their next move is to try logging into your bank, Amazon, PayPal, and email with the exact same combination. This is called credential stuffing, and it is by far the number one way regular people get their accounts broken into. Not fancy hacking. Just password reuse.

The fix isn't "make my password stronger." A stronger password that you reuse is just as vulnerable to this attack. The fix is: a different password on every site. That is only humanly possible with a password manager doing the remembering.

Which one to use

Any of these three. Pick one and move on with your life:

  • Bitwarden — Free forever for personal use, open source, works on everything. What we personally use. Slightly less polished than the paid options but genuinely fine.
  • 1Password — $3/month. The most polished experience. Family plan is $5/month for up to 5 people, which is what we recommend to households.
  • Apple Passwords (built into iOS/macOS) — Free and now genuinely good if your whole family is on Apple. Skip it if anyone uses Windows or Android.

Whichever you pick will be dramatically better than what you're doing now. Do not agonize over the choice. Pick one in the next 60 seconds.

The 20-minute setup

1. Install it on your primary computer and phone

Download from the actual app store or the actual website — not a link in an email, and not the first Google result (some fake versions have shown up). Type the URL yourself: bitwarden.com or 1password.com.

2. Create one really good master password

This is the last password you'll ever memorize. Make it good. Our recommendation: four random words with a number and symbol thrown in. Something like parachute-brie-lantern-echo-42! Real length, easy to type, impossible to guess. Write it down on paper and keep it somewhere physically safe. Yes, on paper. Yes, really.

3. Turn on two-factor for the password manager itself

Every good password manager supports this. Do it during setup. The most common option is a code from an authenticator app on your phone. This means even if someone got your master password, they'd also need your phone. Big deal.

4. Import from your browser

Chrome, Edge, and Safari all have "export passwords" built into their settings. Every password manager has "import passwords." Do this once. You'll immediately have 50+ passwords in your vault. Delete them from the browser after.

5. Turn off password saving in your browser

You want one system, not two. In Chrome/Edge settings, disable "Offer to save passwords." From now on, your password manager fills things in. Your browser stops trying to.

6. As you use the internet this week, let it help

Any time you log in somewhere, the password manager will offer to save that entry. Say yes. Within two weeks it will have everything important. Don't try to do it all in one sitting — you'll get bored and quit.

The five accounts to change the password on first

You don't have to change every password immediately. Do these five this weekend and you've closed 80% of the risk:

  1. Your primary email. Everything else can be reset through this — so it's the crown jewels.
  2. Your bank(s). Obvious.
  3. Amazon. Has your card on file and can ship to any address.
  4. Your work email or work login (if you have one).
  5. Any account tied to your Social Security number — IRS, tax software, health insurance portal, retirement account.

For each, log in, go to settings, generate a new password with the password manager (it'll suggest a 20-character random one), save it, and enable two-factor authentication while you're there. Ten minutes each.

The last thing: why this makes you boring to criminals

Criminals are essentially running a business. They target the easiest 10% of people because that's where the ROI is. When your passwords are unique, long, and locked behind a master + a second factor, breaking into your account isn't difficult — it's economically pointless. They will move on to someone easier.

That is genuinely the entire strategy. Not "make yourself unhackable." Just "make yourself not-worth-hacking." A password manager does that in one weekend.

If you want a technician to walk through it with you: We do password-manager setup in about 40 minutes over a remote session, including your family members' devices. It's included in any tune-up session or available as a standalone. Book one here.

Was this helpful? Share it with someone.

More articles Book a session