Short answer
For most people, a well-designed, maintained and correctly configured password manager is safer than memorising a few passwords and reusing them across websites. A manager does concentrate many credentials in one vault, which makes the master password, trusted devices and recovery process especially important. It also allows every website to receive a completely different long random password, preventing one breach from becoming a chain of account takeovers. The useful comparison is not between concentration and perfect safety. It is between one carefully protected encrypted vault and dozens of repeated or predictable passwords scattered across memory, notes and browsers.
Concentration increases consequence but reduces exposure
The “all the eggs in one basket” concern is legitimate. If an attacker successfully unlocks the vault, the potential loss is substantial. If the user forgets the master password and has no recovery route, they may lock themselves out. A password manager therefore deserves deliberate selection and configuration.
Avoiding a manager, however, does not necessarily distribute risk intelligently. The normal alternative is password reuse, predictable variations, plaintext notes or dependence on email resets. Every small website can then become an entry point. A manager centralises the secret that matters most while making the password disclosed to each external site unrelated to every other password. A breach at one site exposes one credential rather than the person's entire digital identity.
CISA recommends managers as a practical way to create and retain long, random and unique passwords, acknowledging that people cannot realistically memorise many such values. CISA: Use a Password Manager
How a vault protects passwords
A mature manager generally encrypts its vault on the device with a key derived from the master password, then stores the encrypted data locally or synchronises it to a server. Whether the provider can read plaintext, how the key is derived, which metadata remains outside the vault and how recovery works depend on the product. Seeing the name of a strong encryption algorithm is not enough to assess the whole system. Key management, implementation, updates and account recovery matter just as much.
With client-side encryption, theft of the server database normally leaves an attacker needing to attack the encrypted vault and guess the master password. A long unique master password, a strong password-based key derivation design and server-side multifactor authentication can materially increase that difficulty. Reusing a short or predictable master password on other sites undermines the architecture.
“Zero knowledge” is commonly used to describe a design in which the provider does not hold the secret needed to decrypt a vault. It is not an automatic certificate of safety. Users should still look for clear security documentation, credible independent assessment, responsive vulnerability handling, maintained client software and transparent treatment of past incidents.
Can a password manager be hacked?
Yes. Every application, server, browser extension and software supply chain can contain vulnerabilities, and password services can be attacked. The important question is what the attacker obtained: encrypted vaults, unencrypted metadata, saved website addresses, account email addresses, active sessions, or a secret capable of direct decryption. The consequences differ greatly.
When a provider announces an incident, read its specific account of affected data, encryption, master-password risk, sessions, devices and recommended action. Do not assume that the phrase “data breach” means every password became plaintext. Equally, do not assume that “the data was encrypted” means there is nothing to review. The attack boundary and the user's configuration determine the response.
A manager can also reduce a common phishing risk. Autofill normally checks the current domain, so a lookalike site with a different address may not receive the saved credential automatically. This is not absolute protection: a user can manually paste the password, and extensions can contain defects. It nevertheless adds a signal independent of visual judgement.
Cloud-synchronised and local managers
A cloud-synchronised manager is convenient across phones, computers and tablets and can aid recovery after a device is lost. Its encrypted vault and account entry point are exposed to the attack surface of an internet service. CISA's training material likewise notes that cloud managers carry additional risk from transmitting data and storing it on a server outside the user's control.
A local vault gives the user control over its file and synchronisation method, reducing reliance on one hosted service. It transfers responsibility for backup, versioning, device conflict and disaster recovery to that user. A local vault existing only on a failed laptop is not safe. Moving an unencrypted vault or key through an unsuitable channel can be worse than using a reputable hosted design.
The decision should reflect capability and threat rather than treating “local” or “cloud” as a universal verdict. For many individuals, a reputable cloud product with a strong master password and multifactor authentication is safer in practice than self-management without reliable backup. High-risk users and organisations may require hardware security keys, enterprise policy, independent hosting, audit records and more controlled recovery.
Configuration determines much of the outcome
The master password must be exclusive to the vault. A long passphrase made from several unrelated words can work well; length, uniqueness and unpredictability matter more than decorating a familiar short phrase with symbols. Do not make the only backup of the master password another entry inside the same vault. Do not send it through ordinary chat or email.
Enable the strongest multifactor method the manager supports, preferably a security key or phishing-resistant passkey, and at least an authenticator app. Print or write recovery codes and keep them in a physically safe place separate from everyday devices. Protect the associated email account with its own unique password and multifactor authentication, because email often participates in account recovery.
Device security remains part of vault security. Enable device encryption and automatic locking, use a reliable device passcode or biometric unlock, and install operating-system, browser and extension updates promptly. Obtain clients only from official sources, remove extensions no longer required, and avoid unlocking the full vault on an untrusted computer.
What to examine when choosing a manager
Look beyond price and visual design. Is the security architecture documented? Where does encryption occur? Does the provider hold a secret capable of decryption? Does it support multifactor authentication, passkeys or hardware keys? Is there credible independent assessment? Are vulnerability reports and incidents handled transparently? Can data be exported and migrated? Can a support representative bypass the master password too easily? Is the product actively maintained?
Free does not automatically mean unsafe, and paid does not guarantee quality. A browser's built-in manager is already a substantial improvement over password reuse for many people, although cross-platform support, sharing, recovery, audit and strong-authentication features vary. A tool that you will configure correctly, update and use on every important device is more valuable than an elaborate product that remains unused.
Responding to a vault-service incident
Confirm the event through the provider's official site or application rather than clicking an unsolicited “urgent verification” link. Update the client, review sign-in history, end unfamiliar sessions, and confirm that recovery email and multifactor settings have not changed. If the provider says encrypted vaults may have been copied and the master password was weak or reused, replace it and prioritise new credentials for email, finance, identity providers and other high-impact accounts.
Treat exports with special care. Many managers export CSV files in plaintext. Leaving one in Downloads, ordinary cloud storage or a device backup bypasses the vault encryption entirely. Export only for a controlled migration or backup, then secure or remove the file deliberately.
My assessment: concentration should be judged by total risk
A vault compromise has concentrated consequences, but avoiding a manager often distributes risk through reuse, weak variations, plaintext notes and poor domain recognition. The honest comparison is not one fallible vault against twenty perfectly memorised random secrets; it is between two habits people can actually sustain. For most users, rigorously defending one vault is more testable than maintaining dozens of secrets correctly.
One-minute checklist
- Is the master password long, unpredictable and never used elsewhere?
- Do the manager account and main email both use multifactor authentication?
- Are recovery codes stored safely outside the vault?
- Is the device encrypted, locked and updated?
- Did the client and browser extension come from official sources?
- Does every website actually have a different random password?
- Is a plaintext CSV export sitting in Downloads or cloud storage?
- Do I understand recovery if the device is lost or the service is unavailable?
Conclusion
A password manager is not a risk-free container. It is a system for turning dozens of otherwise unmanageable secrets into one system that can receive focused protection. Concentration makes the master password and recovery process more consequential, while sharply reducing reuse, weak passwords and credential stuffing. For most people, the aggregate risk of a reputable manager used correctly is lower than managing digital life through memory and repeated passwords.
Related reading
- Why Shouldn’t You Reuse a Password Across Websites?
- Why Is Two-Step Verification More Important Than a Complex Password?
Continue reading: All articles in How Digital Life Actually Works
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.