Questions & answers

Honest answers about password managers

The questions people actually type into search engines and AI assistants, answered directly. The short answer first, the full story underneath, and the relevant products linked.

Q&A

Which password managers have been breached, and which are independently audited? (2026)

Among the major password managers, the notable breach is LastPass: in 2022 attackers stole backups of encrypted customer vaults, and the slow disclosure cost it years of trust. No comparable breach has hit Bitwarden, 1Password, Proton Pass, or Keeper. The strongest assurance comes from open-source, independently audited tools (Bitwarden, Proton Pass, KeePass), where anyone can inspect the code, plus regularly audited closed-source apps like 1Password. A side note that catches people out: the only free plan that works fully across all your devices is Bitwarden, while NordPass and LastPass limit their free tier to one device.

Read the answer
Q&A

Is a password manager safe?

Yes, a good password manager is far safer than the alternative: inventing and reusing passwords yourself. Pick a service with zero-knowledge architecture and independent audits, like Bitwarden or 1Password, and protect the vault itself with a strong master password plus two-factor authentication.

Read the answer
Q&A

What is a passkey and is it better than a password?

A passkey is a way to sign in without a password: your device proves who you are with cryptography, and you confirm with your fingerprint, face, or PIN. Passkeys are safer than passwords because there is nothing to guess, leak, or phish.

Read the answer
Q&A

What happens if you forget your master password?

With most password managers nobody, not even the company, can recover a forgotten master password; that is the flip side of zero-knowledge security. So set up a safety net in advance: a printed recovery code, emergency access for someone you trust, or 1Password's family recovery.

Read the answer
Q&A

Is your browser's password manager good enough?

For the basics, yes: the managers built into Google and Apple are free, reasonably secure, and better than reusing passwords. A dedicated manager wins once you live outside one ecosystem: it works everywhere, shares more safely, and adds extras like breach scans and secure notes.

Read the answer
Q&A

What makes a strong password in 2026?

Long beats complicated: a passphrase of four or more random words (like "bike-cloud-lemon-plug") is stronger and easier to remember than a short jumble of characters. For everything except your master password, let your password manager generate them: automatically unique and strong.

Read the answer
Q&A

What is two-factor authentication (2FA) and why do you need it?

Two-factor authentication adds a second lock to your account: besides your password, a code from your phone or a confirmation in an app. Even if your password leaks, an attacker still cannot get in. Enable it at minimum on your email, bank, and password manager.

Read the answer
Q&A

How often should you change your passwords?

Not on a schedule anymore: forced rotation every few months leads to weaker passwords and is outdated advice. Change a password immediately when there is a reason: a breach at the service, a phishing scare, or a shared password that should no longer be shared.

Read the answer
Q&A

What does zero-knowledge mean in a password manager?

Zero-knowledge means only you can open your vault: everything is encrypted on your own device with your master password, which the provider never knows. Even if their servers are hacked, or a government comes asking, there is nothing readable to hand over.

Read the answer
Q&A

How do you know if your password has been leaked?

Check your email address on haveibeenpwned.com, the free standard for breach data, or use the built-in breach scanner in your password manager. If a password appears in a leak, change it immediately at that service and everywhere you reused it.

Read the answer
Q&A

Is writing passwords down on paper really that bad?

It is less bad than reusing weak passwords: a note at home is safe from hackers on the other side of the world. But paper does not scale, sync, or back itself up, and it gets lost. For everything except a few emergency codes, a password manager is the better vault.

Read the answer
Q&A

Can a password manager itself get hacked?

The companies behind them can be breached; it happened to LastPass in late 2022. But with a well-built zero-knowledge manager, your passwords stay encrypted, and cracking them depends on the strength of your master password. Pick an audited service and make that master password long.

Read the answer
Q&A

What is an email alias and why use one?

An email alias is a unique, disposable address that forwards to your real inbox. Stores and newsletters never see your real address: if an alias leaks or starts attracting spam, you switch it off and the problem is gone. Proton Pass has aliases built into its password manager.

Read the answer
Q&A

How do you share a password with someone safely?

Not through chat apps or email: messages stick around and are searchable. Use your password manager's sharing feature: it shares encrypted, keeps the password current when it changes, and lets you revoke access. For families, shared vaults are the clean solution.

Read the answer
Q&A

Does a password manager work on all your devices?

Yes, the major managers run on Windows, Mac, Linux, Android, and iPhone, plus as browser extensions. Your vault syncs encrypted across everything. Watch the free-plan limits though: NordPass Free is signed in on one device at a time, LastPass Free locks you to one device type.

Read the answer
Q&A

How do you switch to a different password manager?

Export and import: every manager can export your vault (usually as a CSV file) and every other one can import it, folders included. It takes about fifteen minutes. Delete the export file immediately afterward, because it contains your passwords unencrypted.

Read the answer
Q&A

What is the best free password manager?

Bitwarden is the best free password manager: unlimited passwords and passkeys on all your devices, open source and regularly audited, with no catches. Proton Pass Free is the strong alternative and throws in ten free email aliases.

Read the answer
Q&A

What is the best password manager for families?

1Password Families is the best family pick: five people, shared vaults that actually make sense to non-technical members, and account recovery when someone forgets their master password. Dashlane Friends & Family covers ten people and is the cheapest per person; Keeper Family is the solid third.

Read the answer
Q&A

What is the best password manager for iPhone?

If you live fully in Apple's world, the free Apple Passwords app is surprisingly complete. If you also use Windows or Android, or want more features, 1Password is the best pick on iPhone, with Bitwarden as the strong free option. All three autofill natively with Face ID.

Read the answer
Q&A

What is the best cheap password manager?

Bitwarden Premium is the best buy: $10 a year for a complete, audited manager with 2FA codes and emergency access. NordPass at $1.49 a month on a two-year plan is the slicker option, and RoboForm and Enpass both sit around $2 (guide prices, June 2026).

Read the answer
Q&A

What is the best LastPass alternative?

Bitwarden is the best LastPass alternative: the same features, open source, audited, and free where LastPass charges. 1Password is the premium route with its extra Secret Key, NordPass the modern middle ground. Importing from LastPass takes about fifteen minutes with any of them.

Read the answer