What Is a Password Manager? How It Works and Do You Need One
What a password manager actually does, how its zero-knowledge encryption protects your vault, autofill and passkey support, and whether you need one.

A password manager is an app that generates, encrypts, and stores your login credentials in a vault locked by one master password, then autofills them when you sign in. Most people need one: security agencies including CISA and the Federal Trade Commission recommend them precisely because nobody can reliably memorize dozens of long, unique passwords on their own. The real questions are how the encryption actually protects you, what happens if the company running the service gets breached, and whether a free browser-built-in tool is enough or you need a dedicated app.
What is a password manager, exactly?
A password manager is software that creates long, random, unique passwords for every account you have, stores them in an encrypted database called a vault, and fills them in automatically when you log in. Instead of remembering (or reusing) dozens of passwords, you remember one strong master password — or unlock the vault with a fingerprint, face scan, or device PIN layered on top.
CISA's consumer guidance describes it plainly: "A password manager is an easy-to-use program that generates, stores and even fills in all your passwords," adding that it will flag weak or reused passwords and that "we only need to remember one strong password — the one for the password manager itself." That's the entire value proposition in one sentence: it turns "remember 80 passwords" into "remember one, and protect it well."
Password managers come in three broad flavors, covered in more detail in the comparison table below: free tools built into your browser or phone operating system, standalone apps that work across every browser and device, and enterprise-grade tools built for organizations. This explainer focuses on the first two, since they're what most individual users are choosing between.
How password managers actually work, step by step
When you create an account with a password manager, the app generates a cryptographic key from your master password using a key-derivation function — a deliberately slow hashing process designed to resist brute-force guessing. Bitwarden, for example, runs your master password and email through PBKDF2 (at least 600,000 iterations by default) or the more brute-force-resistant Argon2id to produce a master key, which is then used to encrypt a separate, randomly generated key that actually protects your vault data, according to Bitwarden's documentation on zero-knowledge encryption.
That vault — your stored usernames, passwords, notes, and payment details — is encrypted with a strong symmetric cipher (commonly AES-256) directly on your device, before anything is ever sent to the provider's servers for backup and sync. When you want to view or autofill an entry, your device decrypts it locally using keys that were themselves derived from your master password. The provider's server stores only the encrypted ciphertext, plus some unencrypted account metadata like your email address.
1Password adds another layer: alongside your Account Password, it issues a randomly generated Secret Key that never leaves your devices. Authentication uses a protocol called Secure Remote Password (SRP), which 1Password's support documentation explains lets the app prove it holds the correct password and Secret Key "without sending either of them over the internet," so neither value is ever transmitted or exposed to interception, even over a compromised connection — see 1Password's SRP explainer. Proton Pass follows a similar model: items are encrypted on-device with 256-bit AES-GCM before syncing, and according to Proton's security page, "your data is never accessible to us and only you can decrypt it using your secret password" — a design Proton calls end-to-end, zero-access encryption that also covers metadata, not just passwords.
What happens if the provider gets breached?
This is the question that actually matters, because every cloud service eventually gets probed, and some get breached. The architecture described above — generally called "zero-knowledge" or "zero-access" — is designed so the answer is: very little, if the system works as documented and your master password is strong.
Because encryption and decryption happen on your device, and your master password (and the keys derived from it) are never sent to or stored by the provider, a server-side breach exposes only ciphertext — vault data scrambled with keys the attacker doesn't have. Bitwarden states that it "never stores and cannot access your master password or your cryptographic keys," and that it is "not possible to get your unencrypted data from the Bitwarden cloud servers." The practical trade-off is the same reason recovery is hard: if you forget your master password and haven't set up an emergency-access contact or recovery method in advance, the provider genuinely cannot unlock your vault for you — that's the cost of them not being able to read it either.
This doesn't mean a breach is harmless. An attacker who steals encrypted vault blobs could, in theory, attempt an offline brute-force attack against a weak master password, and account metadata (email addresses, sometimes names or hints) is typically stored in less-protected form and can still leak. That's why providers emphasize a long, unique master password plus two-factor authentication on the vault account itself — the vault encryption protects the contents, but you still need to protect the one key that opens it.
| Type | Examples | Cross-platform sync | Passkey support | Cost |
|---|---|---|---|---|
| Browser built-in | Google Password Manager (Chrome), browser password managers in Safari/Edge/Firefox | Within that browser's ecosystem; limited outside it | Yes, growing fast | Free |
| OS-level (device ecosystem) | Apple Passwords app / iCloud Keychain | Across Apple devices via iCloud; limited on other platforms | Yes | Free |
| Standalone dedicated app | Bitwarden, 1Password, Proton Pass | Any browser, any OS, any device | Yes | Free tier or paid subscription |
How autofill actually works
Autofill is the feature that makes a password manager usable day to day: instead of copying and pasting (or retyping) a 20-character random string, the manager recognizes the login form on a website or app and fills in the matching username and password after you unlock the vault. Under the hood, most managers match saved entries to the exact website domain or app package name, which is also a quiet security feature — a password manager generally won't offer to autofill your real bank credentials into a lookalike phishing site with a different URL, because the domain doesn't match what was saved.
This paste-and-autofill behavior isn't an afterthought; it's baked into password guidance at the standards level. NIST's digital identity guidelines state that verifiers (the login systems you're signing into) "SHOULD permit claimants to use 'paste' functionality when entering a memorized secret," specifically because it "facilitates the use of password managers," which NIST notes are "widely used" and tend to increase the likelihood that people choose stronger passwords in the first place — see NIST Special Publication 800-63B. In other words, a site that blocks pasting into its password field is working against the exact behavior security agencies are trying to encourage.
Password managers and passkeys
Passkeys are a newer, generally stronger alternative to passwords, and most major password managers now store and sync them alongside traditional logins. A passkey is a cryptographic key pair: a public key registered with the website, and a private key that never leaves your device or password manager. Logging in means your device signs a one-time challenge from the site with the private key — there's no shared secret to type, steal, or phish, since the private key is never transmitted.
Apple's documentation on passkey security notes they are "resistant to phishing, are always strong, and are designed so that there are no shared secrets," and that for passkeys stored via iCloud Keychain, encryption keys are "not known to Apple" and brute-force attempts are rate-limited even against Apple's own infrastructure — see Apple's passkey security overview. Google similarly lets you save and sync passkeys through Google Password Manager across Chrome, Android, and (with Chrome set as the autofill provider) iOS, per Google's Password Manager help documentation. Standalone managers like Bitwarden, 1Password, and Proton Pass also generate, store, and autofill passkeys, which is useful if you want your passkeys available outside a single device ecosystem rather than locked to only Apple or only Google devices.
Syncing across your devices
Whichever type you choose, syncing works on the same basic principle: your encrypted vault (or encrypted passkey data) is uploaded to the provider's servers, then downloaded and decrypted locally on each device where you're signed in. Google Password Manager syncs to any device signed into the same Google Account through Chrome; Apple's Passwords app syncs through iCloud Keychain to your iPhone, iPad, Mac, Apple Watch, and Apple Vision Pro. Both are excellent if you live entirely inside one company's ecosystem — and noticeably more limited the moment you mix an Android phone with a Windows PC, or an iPhone with a non-Apple laptop.
Standalone apps were built around the opposite assumption: that people use a mix of devices and browsers. Bitwarden, 1Password, and Proton Pass all offer browser extensions and native apps across Windows, macOS, Linux, iOS, and Android, so the same vault is available regardless of which device or browser you pick up next. That cross-platform reach is also the main reason the two existing 1Password vs. Dashlane and Bitwarden vs. 1Password vs. Proton Pass comparisons on this site focus on standalone apps rather than the built-in options.
Do you actually need a password manager?
For almost everyone, yes — and the alternative is worse than most people assume. The realistic alternative to a password manager isn't "80 unique, memorized, strong passwords." It's password reuse: the same password, or close variations of it, across many accounts, because that's what's actually memorizable without help. That pattern is exactly what makes credential-stuffing attacks work — attackers take passwords leaked from one breached site and try them against other services, betting correctly that people reuse logins.
A password manager breaks that pattern by making unique, random passwords as easy to use as remembered ones. It's also one of the few security upgrades that requires no special technical knowledge: install it, let it generate new passwords as you log into sites over time, and set up two-factor authentication on the vault account itself. If you've ever had a phone number hijacked or an account drained after a breach, a password manager — paired with awareness of techniques like SIM swap scams, which attackers use to intercept SMS-based recovery codes — closes off one of the most common entry points.
The one group that might reasonably skip a dedicated app: people who use only Apple devices, or only an Android phone and Chrome, and have no interest in passkeys or password sharing beyond that ecosystem. The built-in options are genuinely good now and cost nothing. Everyone else — anyone mixing operating systems, sharing logins with family or a team, or wanting a vault that isn't tied to one company's hardware — benefits from a standalone app.
Choosing one: what actually matters
A few practical criteria matter more than marketing claims. First, does it support the platforms and browsers you actually use — check this before anything else. Second, is the encryption model documented and, ideally, independently audited; Proton Pass, Bitwarden, and 1Password all publish security documentation and third-party audit summaries rather than asking you to take zero-knowledge claims on faith. Third, does it support passkeys, since more sites are adding passkey login every year. Fourth, what's the recovery story if you forget your master password — because, as covered above, that's the direct trade-off of encryption the provider can't bypass. Finally, consider whether you need family or team sharing, which varies significantly between the free and paid tiers of standalone apps.
None of this requires picking the "best" password manager in the abstract. It requires picking one that matches how you actually use devices, and then actually turning it on.
What's next
Once you've decided you want a dedicated app rather than your browser's built-in option, the next decision is which one — and that depends more on price, sharing features, and platform support than on security, since the major standalone providers all implement broadly similar zero-knowledge architectures. See our breakdowns of 1Password vs. Dashlane and Bitwarden vs. 1Password vs. Proton Pass for a direct, feature-by-feature comparison. Whichever option you land on, the single highest-impact step is simply turning on a password manager and letting it replace reused passwords one login at a time, then layering two-factor authentication or a passkey on top of your most important accounts.
Frequently asked questions
What is a password manager?
A password manager is an app that generates long, random, unique passwords, stores them in an encrypted vault locked by one master password, and autofills them when you log in to sites and apps. CISA describes it as a program that generates, stores, and fills in your passwords so you only have to remember one.
Are password managers safe if the company itself gets hacked?
Reputable password managers use zero-knowledge (or zero-access) encryption, meaning your vault is encrypted and decrypted on your own device, not on the provider's servers. Bitwarden states it never stores and cannot access your master password or cryptographic keys, so a server breach exposes only unreadable ciphertext, not plaintext passwords.
Can a password manager store passkeys, not just passwords?
Yes. Browser-built-in tools like Google Password Manager and Apple's Passwords app (iCloud Keychain), as well as standalone apps like Bitwarden, 1Password, and Proton Pass, can all generate, store, sync, and autofill passkeys alongside traditional passwords.
Is my browser's built-in password manager good enough?
It's a legitimate option and far better than reusing passwords. Google Password Manager and Apple's Passwords app both sync within their own ecosystem and support passkeys. A standalone app becomes more useful once you mix operating systems or browsers, since it syncs the same vault everywhere rather than staying tied to one company's devices.
What happens if I forget my master password?
Because of zero-knowledge encryption, most providers genuinely cannot decrypt your vault without it, so recovery depends on options you set up in advance, such as an emergency-access contact, a printed recovery key, or account recovery steps documented by your provider. This is the direct trade-off for encryption the provider can't bypass.
Do password managers sync across different devices and operating systems?
Standalone apps like Bitwarden, 1Password, and Proton Pass sync an encrypted vault across Windows, macOS, Linux, iOS, and Android through browser extensions and native apps. Built-in tools sync mainly within their own ecosystem, such as iCloud Keychain across Apple devices or Google Password Manager across Chrome and Android.
Sources
- CISA: Use Strong Passwordscisa.gov
- NIST SP 800-63B: Digital Identity Guidelines, Authentication and Lifecycle Managementpages.nist.gov
- FTC: Creating Strong Passwords and Other Ways To Protect Your Accountsconsumer.ftc.gov
- Bitwarden: Zero-Knowledge Encryptionbitwarden.com
- 1Password: Secure Remote Password (SRP)support.1password.com
- Apple Support: About the Security of Passkeyssupport.apple.com
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


