Skip to content
Saturday, October 10, 2026 · Global Edition
L4 News
BLOCKCHAIN · WEB3 · ASSETS
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
L4 News

Password managers explained: why and how to switch

Reusing the same password across accounts is the habit behind most account takeovers. Here is what a password manager does, and how to move to one without stress.

Password managers explained: why and how to switch
mSecure / Wikimedia Commons (CC0)

A password manager is an app that creates strong, random passwords for every account you have, stores them in an encrypted vault, and fills them in for you when you log in. You remember one master password; the manager remembers the rest. It is not risk-free — you must protect that master password well — but it removes the single most dangerous habit online: using the same password everywhere.

Why does that habit matter so much? When a website gets breached, attackers take the email-and-password pairs and try them on other sites. Reuse turns one breach into many. According to 1Password, 81% of data breaches are caused by reused or weak passwords, which makes unique, random passwords the most effective single defence most people can adopt.

This guide explains how a password manager works, what it can and cannot protect against, and how to switch in an afternoon — judgment-free. If you have reused passwords for years, you are in enormous company, and the fix is simpler than it sounds.

What does a password manager actually do?

Think of it like a locked toolbox for your logins — the analogy breaks down in one important way: a good toolbox can be picked, while a password manager's vault is encrypted so thoroughly that even the company running it cannot read inside. LastPass describes this as a "zero-knowledge" model, where data is kept secret even from the provider itself, according to LastPass.

Three jobs sit inside that vault. First, generation: the manager creates long, random passwords on demand, mixing uppercase and lowercase letters, numbers, and symbols. Second, storage and sync: saved passwords become available across your devices and browsers, so you never have to type a 20-character jumble by hand. Third, autofill: when you reach a login page, the manager offers the right credentials, which also trains you to notice when a page is fake — a skill that pairs well with our guide to phishing red flags in fake exchange emails. We covered a connected angle in Phishing red flags: anatomy of a fake exchange email.

Most managers add a security dashboard that flags weak or reused passwords so you can replace them over time. Microsoft's manager in Edge, for example, bundles a password generator, a breach monitor called Password Monitor, and a Password Health feature that surfaces problem logins, according to Microsoft.

Why are random passwords so hard to crack?

Attackers rarely guess your password the way a person would. They use software that tries billions of combinations per second against stolen lists of password hashes. Length and variety of characters are what slow that process down, and the difference is not subtle.

According to LastPass, a recent report found that a 12-character password made only of numbers would take just 25 seconds to crack, while a 12-character password mixing numbers, upper- and lowercase letters, and symbols would take about 34,000 years. Stretch the length past that — LastPass recommends at least 15 characters including all four character types — and the maths becomes hopeless for an attacker.

Humans are bad at making passwords like this. We pick birthdays, pet names, and patterns, and attackers know it, trying common and predictable choices first, as 1Password notes. That is the core argument for a manager: it removes human taste from the process entirely.

What a password manager does not fix

A manager protects the password layer. It does not make an untouchable. If a service itself is breached, your password may leak even though you did nothing wrong — which is why unique passwords matter: a leak stays contained to one account instead of spreading.

It also does not stop you typing credentials into a fake website. Some phishing kits imitate real login pages well enough to fool autofill, so the habit of checking the web address before you sign in still matters. And it does not defend accounts whose weak point is your phone rather than your password, as our explainer on SIM swap attacks covers. For anything holding money — an exchange account especially — pair the manager with two-factor authentication; our guide on securing a exchange account walks through that combination.

Finally, the manager has its own single point of failure: the master password. Write it down on paper and store it somewhere safe at home. Never reuse it, and never email it to anyone, including "support".

How to switch, step by step

This is an afternoon's work, not a weekend project. No step requires technical skill.

  1. Pick a manager. Options include standalone products such as 1Password or LastPass, or the manager built into a browser you already use, such as Microsoft Password Manager in Edge. Built-in tools are free and simple; standalone products typically add cross-browser support and extra features such as breach monitoring. Microsoft notes its manager requires signing in to Edge with a personal account, and that work or school profiles may restrict some features, according to Microsoft's support documentation.
  2. Set a strong master password. Long and memorable beats short and clever — a phrase of several unrelated words works. This is the one password you will type often, so make it something you can produce from memory.
  3. Turn on two-factor authentication for the manager itself. Most managers support a one-time passcode or a fingerprint scan as a second check. LastPass lists multifactor options among its account protections, according to LastPass. This way, a stolen master password alone is not enough to open your vault.
  4. Start with your most important accounts. Email first — it is the reset key for everything else — then banking, then any account holding money or crypto. Change each password to a fresh generated one, and let the manager save it.
  5. Update the rest gradually. Use the manager's security dashboard to find weak or reused passwords and fix a few each week. There is no deadline; steady beats perfect.
  6. Check the change took. When you edit a stored password, remember that the manager only records what you tell it. As Microsoft's support page puts it, changing a password in the manager does not change it on the website — you have to update both to match.

What this means for your accounts

Our analysis: the switch pays off most in reduced blast radius. Today, one breached site can expose a dozen accounts. After the switch, it exposes one. That containment, plus genuinely unguessable passwords, is what the evidence consistently points to as the highest-value security change an ordinary person can make.

It also changes how you respond to breach news. Instead of wondering which of your thirty passwords was reused, you change the one affected login and move on. And if you keep assets in self-custody, a password manager is one layer among several — our guide to what a hardware wallet does and doesn't protect explains where passwords end and device security begins.

One honest caveat: crypto assets can lose most or all of their value quickly, and no password change is a reason to buy any of them. The goal here is simply keeping what is already yours, yours.

Frequently Asked Questions

Is a browser's built-in password manager good enough?
For many people, yes. Microsoft Password Manager in Edge generates, stores, and monitors passwords without extra extensions, according to Microsoft. Standalone managers usually add cross-browser support and features such as dark web monitoring. The best manager is the one you will actually use consistently.
What if the password manager company gets hacked?
Reputable managers encrypt your vault so the provider cannot read it — LastPass calls this a zero-knowledge, local-only encryption model. A breach of the company's systems should not expose your stored passwords, though you should still change your master password if the provider announces an incident.
Do I have to change every password on day one?
No. Change your email and any money-related accounts first, then work through the rest using the manager's dashboard. LastPass's dashboard helps find and update weak or reused passwords over time. Steady progress across a few weeks is fine and far more likely to actually happen.
Should I still use two-factor authentication?
Yes. A password manager protects the password layer only. Two-factor authentication adds a second check — a code or fingerprint — so a leaked password alone does not grant access. Enable it on your manager itself first, then on email, banking, and any exchange or wallet-related accounts.

Sources

  1. Password Generator - LastPass
  2. Microsoft Password Manager | Microsoft Edge
  3. Password Generator: Strong, Secure & Random | 1Password
  4. View or edit your passwords in Microsoft Password Manager

More from our brands

Part of the VUGA Network

Covers security.