How to Set Up a Password Manager If You've Never Used One
Most people know they should stop reusing the same three passwords everywhere. Actually switching to a password manager feels like a bigger project than it really is, though, which is why so many people who know better keep putting it off. It's genuinely a one-sitting task. Here's exactly how to do it.
I put this off myself for longer than I'd like to admit, mostly imagining some multi-day ordeal of manually re-entering hundreds of passwords one at a time. In reality, the import step alone handled the vast majority of it in a few minutes, and the whole setup, choosing an app, creating the master password, importing, and testing autofill, took under half an hour start to finish.
Choosing a password manager (what actually matters)
A handful of well-established options exist, and for a first-time setup, the differences between the major ones matter far less than actually picking one and starting. That said, a few things are worth checking before you commit.
Cross-device support matters if you use more than one device, which is nearly everyone. Confirm whatever you pick has apps or browser extensions for every platform you actually use, phone, laptop, any other device where you log into accounts.
Look for one with a genuinely free tier if you want to try it without commitment first. Most reputable options offer a functional free version covering the core password storage and autofill features, with paid tiers adding extras like secure file storage or advanced sharing options most people don't need immediately.
Check whether it supports biometric unlock (fingerprint or face recognition) on mobile, since this is what actually makes day-to-day use fast rather than annoying, typing a long master password every single time you need to log into something.
Creating and protecting your master password
This is the single most important step in the entire process, worth more attention than every other step combined.
Your master password is the one password that unlocks access to every other password stored inside the manager. Unlike your regular website passwords, this one you actually need to remember yourself, since most password managers can't recover it for you if you forget it (this is intentional, and it's a genuine security feature, not an oversight, since a company that could recover your master password would also represent a security weakness itself).
Make it long rather than complex. A random string of unrelated words, something like "correct-horse-battery-staple" style, tends to be both easier to actually remember and harder to crack than a shorter password stuffed with symbols and numbers you'll struggle to recall under pressure. Aim for at least four or five random words strung together, ideally with a couple of numbers or a symbol mixed in somewhere memorable to you specifically.
Do not reuse a password you've used anywhere else for this. Given that this one password protects everything else, it needs to be genuinely unique, not a variation of something you've typed into other sites before.
Write it down somewhere physical and secure if you're worried about forgetting it, a piece of paper stored somewhere safe at home, not a note on your phone or a file on your computer, which defeats the purpose of protecting it in the first place. This isn't paranoid, losing access to your master password means losing access to every password you've stored, so a physical backup is a reasonable precaution during the first few weeks while it's still new and unfamiliar.
Importing passwords saved in your browser
Most people already have a scattered collection of saved passwords sitting in their browser (Chrome, Safari, Firefox, whichever you use), and starting completely from scratch would mean re-entering credentials for every single account, which is exactly the kind of friction that makes people abandon the switch halfway through.
The good news: nearly every major password manager offers a direct import tool for exactly this situation. The general process, which varies slightly by browser and by which password manager you've chosen, involves exporting your saved passwords from the browser as a file (usually a CSV), then importing that same file into your new password manager's import feature, typically found in its settings menu.
A genuinely important step people skip: after importing, delete the saved passwords from your browser itself, and turn off the browser's built-in password-saving feature going forward. Otherwise you end up maintaining two separate, gradually diverging password stores, which defeats the purpose of consolidating into one properly secured place and creates confusion about which version of a password is actually current.
Also worth doing during this same session: the exported CSV file sitting temporarily on your computer contains every one of your passwords in plain, readable text. Delete that file securely once the import is complete, don't just leave it sitting in your downloads folder indefinitely.
Setting up autofill safely
Autofill is what makes a password manager actually convenient day to day, automatically filling in your username and password when you visit a site, rather than you needing to manually open the app and copy-paste every time.
Install the browser extension for your chosen password manager if you haven't already, this is typically a separate installation from the main app and is what enables the autofill functionality specifically within your browser.
Grant the extension permission when your browser asks, this is normal and expected for a password manager extension to function, it needs to read the page to know when a login form is present and fill it in correctly.
Test it on a site you use regularly before assuming it's fully working. Log out of an account, then log back in and confirm the autofill prompt appears correctly. It's worth catching any setup issues on a low-stakes account rather than discovering something's misconfigured on your bank's website at an inconvenient moment.
Enable biometric unlock on mobile if your device and the app both support it, this is what turns "open the app, type the master password every time" into a quick fingerprint or face scan, which genuinely determines whether you'll keep using it consistently or start finding workarounds out of pure friction.
Using it going forward (not just for imported passwords)
Importing your existing passwords gets you started, but it also imports whatever weak or reused passwords you already had, which doesn't actually fix the underlying problem on its own. The real value shows up going forward, every time you create a new account or update an old password.
Most password managers include a built-in password generator, accessible right from the browser extension when you're creating or changing a password on any site. Use it. It creates a genuinely random, long password you'll never need to remember yourself, since the manager stores and autofills it from then on. There's no real reason to type your own password anymore once this is set up properly, letting the generator handle it removes the temptation to fall back into reusing something familiar out of habit.
Many password managers also include a security audit or "weak password" report, scanning your stored passwords and flagging ones that are short, reused across multiple sites, or have appeared in a known data breach. Running this once after your initial import, then periodically afterward, say every few months, is a genuinely useful habit for gradually replacing your weakest passwords with generated ones rather than trying to fix everything at once on day one.
Frequently asked questions
What happens if I forget my master password?
This depends on your specific password manager's recovery options, which vary. Some offer account recovery through a secondary method you set up in advance, like a recovery key you're given during setup and told to store somewhere safe. Others genuinely cannot recover it at all, by design, meaning forgetting it means permanently losing access to everything stored inside. This is exactly why the master password advice above (write it down physically, somewhere safe) matters so much, particularly during the first few weeks while you're still building the habit of remembering it reliably.
Are browser-saved passwords actually unsafe?
Not catastrophically unsafe, but genuinely less secure than a dedicated password manager in a few real ways. Browser password storage typically has weaker protection if someone gains access to your actual device while you're logged in, and browsers generally offer less robust tools for generating genuinely random passwords or auditing which of your passwords are weak, reused, or have appeared in a known data breach, features dedicated password managers usually include.
Can I use a password manager across multiple devices?
Yes, this is one of the core features, not an add-on. Once set up, your stored passwords sync across every device you install the app or extension on and log into with the same account, phone, laptop, tablet, whatever you use. This is precisely why cross-device support was worth checking before picking one in the first place, since a password manager that only works on a single device defeats much of its own purpose.

0 Comments