Setting Up a Password Manager and Passkeys
A password manager eliminates reuse; passkeys remove the shared secret entirely on supported sites. Set recovery before migrating your most important accounts.

A password manager solves the practical problem that humans cannot remember a different long random password for every account. A passkey goes further on supported services: it replaces the reusable password with a cryptographic credential tied to your device or credential provider and is designed to resist phishing. The safest setup is not “install an app and import everything.” Choose a trustworthy manager, secure its master account and recovery method, import or create unique passwords, fix reused credentials, then add passkeys to high-value accounts where supported. Test recovery before you delete old notes or move your entire household into the new system.
Choose the manager by recovery and platform fit, not by a feature checklist
Decide whether you need Windows, macOS, iPhone, Android, browser support, family sharing, business separation, emergency access, or self-hosting. Prefer a provider with strong encryption design, independent security review, export capability, and a clear breach-response history. A manager that your family refuses to use will not solve reuse. Likewise, a sophisticated system that cannot be recovered when a phone is lost may create a larger operational risk than the password problem it was meant to fix.
Create a strong master passphrase that is unique to the manager. Enable the strongest MFA the service supports. Store the recovery key or emergency method somewhere physically or digitally separate from the logged-in device. Do not put the only recovery secret inside the vault it unlocks.
Import first, then treat reuse as the priority queue
Browser and phone exports can move saved credentials into the manager, but exports are often plain-text files. Import them on a trusted device, confirm the vault contains the records, and securely delete the export. Then run the manager’s security audit to identify reused, weak, and known-compromised passwords.
Start with email, financial, tax, cloud, carrier, and social accounts. Replace reused credentials with random unique passwords. Work outward in manageable batches. You do not need to change hundreds of low-risk accounts in one night if the most valuable recovery accounts are already unique and protected.
| Credential method | Phishing resistance | Main strength | Main operational risk |
|---|---|---|---|
| Memorized password | Low when reused or entered on look-alike sites | Works almost everywhere | Reuse, guessing, phishing |
| Password manager-generated password | Better because every site gets a unique secret | Stops credential reuse across services | Vault recovery and device security matter |
| TOTP authenticator + password | Moderate | Independent second factor for many sites | Real-time phishing can still trick users into entering the code |
| Security key | High | Hardware-bound phishing resistance | Need a backup key or recovery path |
| Passkey | High when implemented correctly | No reusable shared password; easy device authentication | Cross-device recovery and account-provider ecosystem need planning |
Passkeys are strongest when the recovery account is strong too
A passkey can prevent a fake website from tricking you into handing over a reusable password, but the account may still allow fallback recovery through email, SMS, or customer support. Review those fallback paths. If your passkey-protected bank can be reset through a weak email account, secure the email. Add more than one trusted device or a second passkey where the service permits, so losing one phone does not force you into an insecure emergency recovery.
Do not delete a working password or recovery method until you have tested how the passkey works on another device you actually use. Adoption is still uneven, and different platforms sync passkeys in different ways.
Family sharing needs least privilege, not one giant shared vault
Use shared collections or family groups for household accounts that genuinely belong to everyone, such as utilities or streaming services. Keep individual bank, health, tax, and work credentials private. For a shared financial or estate responsibility, use the manager’s emergency-access or designated-sharing feature rather than giving everyone the master password.
If children use the manager, decide which accounts they can manage themselves and which recovery details a parent should hold. The goal is to teach unique credentials without normalizing family-wide access to sensitive personal accounts.
- □ Pick a manager that supports every device and browser you rely on and has a recovery method you understand.
- □ Create a unique master passphrase and protect the manager account with strong MFA.
- □ Store recovery material outside the vault and test it before migrating everything.
- □ Import credentials on a trusted device and securely delete any plain-text export used for migration.
- □ Replace reused passwords on email, financial, tax, carrier, and cloud accounts first.
- □ Add passkeys or security keys to high-value accounts and maintain at least one safe backup path.
Do not turn the manager into a single point of casual access
Lock the vault automatically, require device authentication, keep operating systems current, and avoid leaving an unlocked vault on a shared computer. A password manager concentrates secrets, which is why the master account and endpoint security deserve more care than an ordinary website password. That concentration is still safer than reuse when the vault is properly protected, because one breached website no longer exposes the password for ten others.
For work, keep business credentials in the employer-approved manager rather than mixing them into a personal family vault. Offboarding becomes much cleaner when shared business secrets can be revoked without touching personal accounts.
Keep a paper or offline recovery plan for catastrophic loss
Imagine your phone is stolen while traveling and your laptop is at home. Can you recover the manager without the stolen phone? Can you access the recovery email? Does a trusted person know where the emergency key is? Write a short plan that does not contain every password but explains where the recovery material lives and which provider support path is legitimate. This is especially important for families relying on one technically skilled person.
The migration is complete when reuse is near zero, not when the app is installed
Check the manager’s audit after a few weeks. The number of reused passwords should be falling, critical accounts should have strong MFA or passkeys, and recovery should have been tested. Keep updating new accounts automatically. A manager becomes valuable only when it changes behavior: unique credentials by default, secure sharing, and a recovery method that can survive a lost device or family emergency.
Questions specific to Setting Up a Password Manager and Passkeys
Is a password manager safer than remembering a few passwords?
For most people, yes because it makes unique random passwords practical and reduces credential reuse. The manager account itself must be strongly protected and recoverable.
Are passkeys the same as passwords stored in a manager?
No. A stored password is still a shared secret sent to the website. A passkey uses public-key cryptography and is designed so a phishing site cannot simply collect and replay the same secret.
Should I change every password immediately after installing a manager?
Prioritize high-value and reused credentials first: email, finance, tax, cloud, carrier, and social accounts. Then work through lower-risk accounts in batches.
What happens if I lose the phone that holds my passkeys?
Recovery depends on the platform and provider. Add a second trusted device, backup security key, synced passkey provider, or other safe recovery method before relying on one device.