Here’s a painfully ordinary story.
Someone uses the same password for Gmail, Netflix, LinkedIn and a shopping site they forgot about years ago. It’s a decent password, by normal human standards. It has a capital letter, a number and one of those exclamation marks websites keep requesting as if punctuation can defeat crime.
Then the forgotten shopping site is breached.
Over the next few weeks, login alerts arrive from several services. Two evenings disappear into changing passwords, checking bank statements and trying to remember which accounts shared the same variation.
The weakest account had become a spare key to everything else.
This is why I think password managers are no longer optional for people who use the internet regularly. You can avoid them, of course. You can also keep twenty different passwords in your head. Most of us won’t. We’ll create one “strong” password, add 2026 to it and reuse it until something unpleasant happens.
Memory is the wrong tool for this job
Human beings are good at remembering stories, faces and embarrassing comments made during office meetings.
We’re not good at remembering forty long, random strings.
So we compromise. There’s the main password, the work version, the banking version and the version used for websites that seem slightly untrustworthy. Perhaps the last one ends with 123. It feels organised because there are categories.
Attackers don’t care about our categories.
When login details from one service are exposed, criminals can try the same credentials on other sites. Government security guidance keeps repeating the same boring advice: use a long, random and unique password for every account, preferably generated and stored by a password manager. NIST’s current guidance also says services should support password managers and autofill because they make stronger passwords more likely.
Living with that advice without software is ridiculous.
The one password that changes the arrangement
A password manager stores your logins and fills them in when needed. Instead of remembering every password, you remember the password that unlocks the manager.
Yes, this puts a lot of importance on one account.
People often say, “Isn’t that keeping all your eggs in one basket?” Fair question. But the alternative most people are using is not forty beautifully protected baskets. It’s the same egg copied across Gmail, Amazon, Instagram and a food delivery app.
A reputable password manager protects the vault with encryption, while a strong master passphrase and multifactor authentication make access harder for anyone who isn’t you. No system is risk-free. Neither is your current habit.
Security choices are rarely between perfect and dangerous. They are between one manageable risk and several messy ones you’ve stopped noticing.
Starting is irritating for about an hour
I won’t pretend the setup is delightful.
You install the manager, create the main passphrase, add the browser extension and begin moving accounts into it. Some logins import neatly. Others appear twice. A banking app may refuse autofill for reasons known only to the banking app.
Then you discover how many accounts you have.
A typical password clean-up uncovers three accounts for the same clothing website, an old broadband login and a streaming service last used during lockdown. Half the exercise becomes digital archaeology.
You do not need to fix everything on day one.
Start with email. Email controls password resets for much of your digital life, so it deserves a unique generated password and strong MFA. Then deal with banking, payment apps, social media, cloud storage and your main shopping accounts.
The forgotten gardening forum can wait.
Browser password managers are not fake password managers
Some security advice becomes unnecessarily snobbish here.
If Chrome, Safari, Edge or your phone already offers to generate and save unique passwords, using that is much better than reusing one memorable password everywhere. For many people, the built-in option is enough. Convenience matters because security tools people dislike tend to become security tools they stop using.
Dedicated password managers make more sense if you move between operating systems, share selected credentials with family or colleagues, want stronger organisation, or need emergency-access features.
But don’t spend three weeks comparing applications while continuing to use Rahul@123 on twelve sites.
Choose a reputable option. Turn on MFA. Learn how account recovery works.
Then get on with your life.
Autofill does something memory cannot
A useful side effect of password managers is that they can help you notice fake login pages.
Your memory sees a page that looks like Microsoft or LinkedIn and starts typing. A password manager usually matches credentials to the website address. If it refuses to autofill, that pause is useful. Maybe you’re on the wrong domain. Maybe the link in that urgent email was not as official as it claimed.
This is not complete phishing protection. But the manager is checking something humans routinely ignore while rushing—the exact address.
The funny part is that convenience, not fear, is what makes this habit stick. After a few weeks, manually typing passwords feels primitive. You stop clicking “Forgot password” every month. New accounts get nonsense passwords you never need to see again.
Good security often survives because it removes work.
Don’t stop at the vault
A password manager does not make an account untouchable.
Use multifactor authentication on important accounts, especially email, financial services and the password manager itself. Authenticator apps and security keys generally offer stronger protection than codes sent by text when those options are available. CISA and the FTC both recommend pairing unique passwords with MFA so a stolen password alone is not enough to enter an account.
Store recovery codes somewhere safe, not in a screenshot floating through your photo library.
Also, don’t approve login prompts you did not start. A second factor works poorly when someone taps “Yes” simply to make the notification disappear.
Passkeys will reduce our dependence on passwords over time, and I’m happy about that. Still, plenty of websites will ask for them for years. NIST’s public guidance continues to recommend password managers, MFA and long passphrases where passwords remain necessary.
So make one strong passphrase you can remember. Protect the manager with MFA. Let it generate the rest.
You should not know your Netflix password.
That’s the point.





