Reusing passwords is risky: if one site is breached, criminals try the same details elsewhere. A password manager solves this by remembering unique, strong passwords for you.
Step 1: Choose a reputable password manager
Look for strong encryption, cross-device sync, independent security audits and two-factor authentication. Many browsers and operating systems also include built-in managers.
Step 2: Create a strong master passphrase
Use four or more random, unrelated words — for example, a phrase built from words you pick at random from a book. Length makes it strong; randomness makes it hard to guess. Never reuse it anywhere else.
Step 3: Turn on two-factor authentication
Protect the password manager itself with an authenticator app or security key, then store recovery codes somewhere safe offline.
Step 4: Replace weak and reused passwords
- Start with email — it’s the key to resetting everything else.
- Then banking, shopping and social media accounts.
- Use the manager’s generator to create long, random passwords.
- Check its security dashboard for weak or reused entries.
Consider passkeys too
Where a site supports passkeys, they can replace passwords entirely — and many password managers can store them.