Accounts · Analysis
Password Manager or Just the Browser?
Browser storage is much better than it used to be, and still loses on three specific counts. What each approach really protects.
The advice to use a password manager is universal. The reason is usually stated as "so you can use different passwords everywhere", which is correct and incomplete — and browsers now do that too, which makes the real comparison more interesting.
What browser password storage does well
It is already there, which means people use it, and a used mediocre tool beats an unused good one.
It is encrypted, on all major browsers, tied to the device or account.
It syncs across your devices signed into the same account.
It generates strong passwords and flags reused ones.
It warns about breached credentials by checking against known exposure lists.
For someone who currently reuses one password everywhere, switching to browser storage is a very large improvement at nearly zero cost. That is worth saying plainly, because the perfect option puts people off doing anything.
Where it falls short
It is tied to a browser. Passwords for applications, servers, wifi networks, licence keys and anything outside a web page have nowhere to live. People keep those in a notes file, which is where the security actually fails.
Sharing is poor or absent. Household or team credentials end up in a message thread.
It stores passwords and little else. Recovery codes, security question answers, software licences, passport numbers, account numbers — a manager holds these encrypted; a browser does not.
The unlock model is weaker. Browser storage is frequently accessible to anyone with the unlocked device, without a separate prompt. A manager can require its own authentication and lock on a timer.
Migration is harder later. Exporting from a browser is possible and clumsier than moving between managers.
What a dedicated manager adds
Everything not a web login. This is the main practical gain.
Secure sharing with named people, revocable.
Its own lock, independent of the device.
Cross-browser and cross-platform without being tied to one vendor's account.
Better auditing — reused, weak, old and breached passwords in one view.
Storage for the things people currently keep in plain text, which is frequently the largest real risk in someone's setup.
The objection worth taking seriously
Putting every password in one place creates a single point of failure. This is true and it is the right question to ask.
The answer is that the alternative is worse. Reused passwords mean one breach anywhere compromises everything, and that happens constantly. A manager concentrates risk into one well-defended place instead of spreading it across dozens of poorly defended ones.
Reduce the concentration risk deliberately:
Protect the manager with a strong, unique passphrase you have never used elsewhere and a second factor, preferably a hardware key or passkey.
Keep your email account's password and its recovery codes outside the manager, or at least also outside it. If the manager is unavailable, you need a way back into email, which resets everything else.
Export an encrypted backup periodically and store it offline. Vendors go out of business and accounts get locked.
Know the vendor's history. Managers have been breached. What matters is whether the vaults were encrypted such that the breach did not expose contents, and whether the vendor disclosed promptly and completely.
Choosing one
Does it store more than passwords? Notes, files, recovery codes.
Where is the vault encrypted? It should be encrypted on your device before it leaves, so the vendor cannot read it.
Can you export? In a standard format, on demand, without the subscription being active. A manager you cannot leave is a trap.
Does it support passkeys?
Is there a usable free tier or a fair price? Many people abandon a manager when it starts charging for the sync they depend on.
How does account recovery work? Some managers cannot recover your vault by design, which is a security feature and means losing the passphrase loses everything. Understand which model you are choosing.
Moving without a bad afternoon
Do not migrate everything at once. Export from the browser, import into the manager, and let both coexist for a few weeks.
Change the important passwords as you go, rather than importing weak ones and leaving them.
Start with email, finances and anything holding payment details. Twenty accounts covers most of the risk.
Turn off browser saving once the manager is working, or you will accumulate two divergent copies and never know which is current.
Then delete the notes file. That is the actual win.