Set up a password manager on the devices you use, secure its main account with a long, unique passphrase and multi-factor authentication (MFA), then use its generator and autofill for different passwords on every account. Start with new signups and replace reused or weak passwords on existing accounts over time. A manager makes unique passwords practical, but it cannot tell a genuine sign-in page from a fake one.
1. Choose a password manager that fits your devices
Pick a manager that works on your phone, computer, and browsers, and that you can use wherever you need to sign in. Check that it offers password generation, autofill, syncing across your devices if you need it, and MFA for the manager account. Also consider its recovery options and how you could import or export passwords if you switch later.
NIST recommends using a password manager for accounts that require passwords and advises choosing one that supports MFA. Apple and Google both document built-in options; neither is the right choice for everyone. Your devices and account ecosystem are practical starting points. NIST guidance
Google Password Manager
Google Password Manager can suggest unique passwords, save and autofill them, and alert you about compromised passwords. Google documents using saved passwords across devices by signing in to Chrome with your Google Account. Its help page covers setup and security features; exact controls can vary by platform. Google Chrome Help: Get started with Google Password Manager
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Apple Passwords
Apple’s Passwords app supports passwords, passkeys, and verification codes on iOS 18, iPadOS 18, macOS Sequoia, and visionOS 2. Apple documents AutoFill and iCloud Keychain syncing on supported Apple devices. Available features and controls depend on the operating-system version and the sites or apps you use. Apple Support: Use the Passwords app
Third-party managers
For a third-party option, compare MFA for the manager login, device and browser coverage, syncing, recovery, import and export, and whether it checks for weak, reused, or exposed passwords. These criteria help you assess fit; the guidance here does not establish that any particular vendor is best.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
2. Secure the manager before adding passwords
- Create a long, unique primary password or passphrase. Do not reuse a password from another account. Choose a manager that supports MFA and turn it on for the manager account.
- Save recovery information safely. Follow the manager’s recovery instructions and keep the information somewhere you can access if you lose your usual device or sign-in method. Losing your only recovery method can leave you unable to regain access.
- Enable syncing and autofill where needed. Use the official instructions for your operating system and browser. On iPhone, Apple documents Password AutoFill under Settings > General > AutoFill & Passwords. Google documents signing in to a Google Account in Chrome and allowing Chrome to use saved passwords across devices.
A strong vault password matters because it protects many saved logins at once. CISA advises using a long, unique, random primary passphrase to protect a password manager. CISA Secure Our World: Passwords Tip Sheet
3. Use generated passwords for new accounts
- When you create an account, use the manager’s password generator rather than making up a password or reusing one.
- Accept the suggested password and save it in the manager when prompted.
- At your next sign-in, use the manager’s autofill feature and confirm that it fills the correct account’s login fields.
- If a site rejects the generated password, adjust the manager’s length or character options to meet that site’s stated rules. Generate a different password for that account; do not fall back to a password used elsewhere.
On iPhone, Apple documents the flow for automatically filling in strong passwords during signup. Apple iPhone User Guide: Automatically fill in strong passwords on iPhone
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
4. Replace reused and weak passwords on existing accounts
You do not need to change every password in one sitting. Use the manager’s security review, if available, to identify reused, weak, or exposed credentials. As a practical priority, update accounts whose compromise could make it easier to take over other accounts, such as your primary email, then address financial accounts and other important services. This is a useful order for managing the work, not a sequence prescribed by NIST or CISA.
- Open the account on its genuine website or app and change its password in the account’s security settings.
- Generate a new, distinct password with your manager and save it immediately.
- Sign out and back in, or otherwise confirm the new password works, before moving on.
- If an alert says a password was exposed, change it on the affected service. If you reused it elsewhere, change those other accounts too, giving each its own password.
5. Turn on MFA and keep recovery current
Turn on MFA, sometimes called 2-Step Verification, for important accounts wherever it is offered. It can help protect an account even if its password is compromised. If a service offers a choice of factors, consider a stronger option it supports, and make sure you understand how account recovery works. No factor removes every phishing or recovery risk.
Rank #4
For your Google Account, Google advises adding recovery information and enabling 2-Step Verification. Keep recovery details current on other services too. Google Password Manager setup and security guidance
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Know what a password manager can—and cannot—do
Distinct passwords limit the damage from password reuse: if one service is breached, that password should not unlock your other accounts. But a manager cannot stop you from entering a password on a fake sign-in page. Check the site or app you are signing into, especially when you arrived through a message or unexpected link.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
NIST explains that a long, complex password will not help if you send it to an attacker. It also discusses passkeys as an alternative where a service supports them. Passkeys are not passwords; using one does not mean you must stop using a password manager for accounts that still require passwords. NIST password, MFA, and passkey guidance
7. Make password reviews a routine
- Investigate alerts about exposed or reused passwords and change affected credentials on the real service.
- Update recovery information when your email address, phone number, or recovery method changes.
- When you add a new account, generate and save a fresh password rather than reusing an existing one.
- If you change devices or managers, follow the official sync, import, or export instructions and confirm you can access your saved logins before removing the old setup.
NIST’s password guidance, updated August 20, 2025, uses an illustrative rate of 100 billion guesses per second for a modern PC when explaining offline password guessing. It also gives an example in which an eight-character lowercase-letter password would take about 200 billion guesses. Those figures illustrate the example’s assumptions; they are not a benchmark for every attacker, device, password, or hashing setup. NIST: How Do I Create a Good Password?
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

