Do You Need a Password Manager? (Yes. Here's Which One.)
I work on PCs where accounts have been taken over. Someone's Amazon account placing orders in Eastern Europe. An email account full of sent spam. A bank account with unexplained login attempts. Almost every time, the story is the same: one password reused across multiple sites, one of those sites got breached, and automated bots started trying those credentials everywhere else.
It's not sophisticated hacking. It's called credential stuffing, and it's completely automated. No targeted effort required.
How credential stuffing works
When any website gets breached, the stolen data — typically email addresses and hashed passwords — gets added to large lists that circulate online. The passwords get cracked over time. Automated tools then test these username and password pairs against thousands of other sites simultaneously. If you used "Sarah1987!" on a small forum that got hacked in 2020, bots have been trying that on your email, your bank, and your Amazon ever since.
You can check if your email address appears in any known breaches at haveibeenpwned.com. It's run by Troy Hunt, a security researcher, and it's a legitimate service.
What browser password storage does — and doesn't
Chrome saves passwords tied to your Google account. If you're signed in, they sync to Google's servers and you can see them all at passwords.google.com. Edge does the same via your Microsoft account. Firefox uses a Firefox account for sync, or stores them locally if you're not signed in.
The convenience is real. Zero setup, already there, works reasonably well. For a lot of people it's better than nothing and it's genuinely fine as a starting point.
But it has real limitations. If your Google or Microsoft account gets compromised, every saved password goes with it. It's all in one basket, and Google and Microsoft accounts are extremely attractive targets precisely because so many people store credentials there. There's no separate master password when your PC is already unlocked — someone sitting down at your logged-in machine can open Chrome settings and view saved passwords immediately. And there's no cryptographic guarantee that Google or Microsoft can't access your passwords. Their privacy policies cover this loosely.
What a dedicated password manager adds
The key difference is zero-knowledge encryption. Your passwords are encrypted on your own device before being sent anywhere. The company running the manager can't decrypt your vault — even if they're hacked, attackers get encrypted data that's useless without your master password. This is a fundamentally different security model from browser storage.
You also get a separate 2FA layer on the vault itself. Even on an unlocked PC, accessing the vault requires a second factor. A cross-browser and cross-device vault — one set of credentials that works in Chrome, Firefox, Edge, on your phone, on any device. And a security audit that flags reused passwords, weak passwords, and credentials that appeared in known data breaches.
Which one to use
Bitwarden is what I use and what I recommend to everyone who asks. It's open source — the code is publicly available for anyone to inspect, which is a meaningful security advantage over closed-source alternatives. It's had independent security audits by Cure53 (2020 and 2022) which confirmed the no-logging and encryption claims. The free tier covers unlimited passwords on unlimited devices, which is more generous than almost any competitor. Premium is $10 a year and adds things like 2FA code generation inside the app. Start with the free tier.
1Password is worth mentioning if you want something more polished or are setting up multiple people. $2.99/month for an individual, $4.99/month for a family plan covering up to five people — that family pricing is decent value. Very good across all platforms. Has a Travel Mode that temporarily removes vaults from your device, which is genuinely useful.
Dashlane had a good free tier for years and then changed it to one device only, which killed the free tier's usefulness. Fine on paid but Bitwarden is better value.
KeePass is for people who don't trust any cloud storage with their passwords. Completely local, no cloud component, open source, free. Your passwords live on your device. Sync manually via Dropbox, a USB stick, or not at all if you only use one machine. More manual than the cloud options but it works well once set up, and you have complete control.
Getting started with Bitwarden
- Go to bitwarden.com and create a free account.
- Choose a master password. Four random words is the right approach — length beats complexity, and "correct-horse-battery-staple" style passwords are harder to crack than "P@ssw0rd123!" and much easier to remember. Write it down somewhere physical — a notebook in a drawer, not a Post-it on the monitor and not in a notes app on the same device. Losing the master password means losing the vault.
- Install the browser extension (Chrome, Firefox, Edge, Safari) and the mobile app for iOS or Android.
- Import your existing passwords from Chrome: Chrome Settings → Autofill and passwords → Password Manager → the three-dot menu → Export passwords → save as CSV. In Bitwarden: Tools → Import data → select Google Chrome as the format, upload the file. Done.
- Enable 2FA on your Bitwarden account: Account Settings → Security → Two-step login. Use Google Authenticator or Authy.
Something the extension does that people miss at first: when you save a login you can store the website URL with it. The browser extension then shows a small launch button next to that login. Click it and the site opens in a new tab, login ready to autofill. Once your vault has a few dozen entries, it becomes how you open most of the sites you log into. Better bookmarks.
Browser storage is better than reusing passwords — if that's what you're currently doing, it's an improvement and I'm not going to tell you to bin it immediately. But a dedicated manager with zero-knowledge encryption is meaningfully better, and Bitwarden is free. Good password hygiene stops account takeovers, but if something's already on the machine itself, that's a different problem. My virus removal service in St Helens covers that side of things.
Mark has been fixing computers since the late '90s and went self-employed in 2008. Based in St Helens since 2013, he works evenings and weekends from his home in Laffak — friendly, affordable repairs for PCs, laptops, and Macs. See reviews on Google
Think your account might have been compromised?
If you've had suspicious logins, unexpected password reset emails, or think something's accessing your accounts — bring the PC in and I'll take a look.
★★★★★"Very quick diagnosis and repair of laptop. Really good but most of all good value, as a person with limited tech knowledge i often get ripped off on repairs but not with your local tech guy is honest and professional. Highly recommended 5★ service!"
— SMT, via Google