Editor’s correction, September 9, 2026: the previous headline wrongly dismissed browser password managers as a category. We have removed outdated product prices, unsupported security guarantees and oversimplified migration advice.
A good password routine should reduce the temptation to reuse the same secret everywhere. For many people, the manager already built into their browser or device is a practical way to do that. A separate app can offer useful features, but installing one is not a prerequisite for taking password security seriously.
Browser managers are password managers
The UK’s National Cyber Security Centre explicitly says that saving passwords in a browser or device manager can be safe on your own devices. Its password-management guidance distinguishes that situation from saving credentials on a public or shared computer. It also stresses protecting the devices and accounts on which the manager depends.
A separate manager may be useful when you regularly move between different browsers and operating systems or need particular sharing features. That is a question of requirements and usability, not proof that everything built into a browser is inherently insecure. The best fit is one you can use consistently and protect properly.
Choose a routine before choosing a brand
List the devices you actually use. Consider whether you need family sharing, workplace access, an offline option or help recovering access after losing a device. Check the provider’s current documentation for those requirements. Prices and plan boundaries change, so our previous fixed-price recommendations should not have been presented as permanent facts.
Next, decide which manager will be your main record. Two competing save prompts can make it harder to know where a new password ended up. You do not have to migrate everything in a single rushed session: a small, verified change is preferable to a mass import whose result you have not checked.
Protect access to the vault
CISA’s password-manager guidance recommends choosing a manager that offers multifactor authentication and taking care not to lose its primary authentication method. Follow your provider’s recovery instructions and keep the recovery material in a place appropriate to its sensitivity.
Encryption is valuable, but describing stolen encrypted vaults as universally useless was too strong. Security depends on the design, configuration, strength of the secrets protecting the vault and condition of the device. No product category deserves a blanket guarantee that a breach cannot matter.
More than one layer
Multifactor authentication adds protection, but its forms are not identical. CISA’s guidance on phishing-resistant MFA distinguishes methods designed to resist phishing from codes and prompts that attackers may still exploit. Do not assume every authenticator code is confined to one physical phone or that entering a code makes a suspicious login safe.
For migration, use the official instructions for the exact source and destination. Check whether an export contains readable passwords, protect it accordingly, verify the import and remove temporary exports when they are no longer needed. Avoid deleting your old working setup before confirming that you can unlock the new one and reach important accounts.
The useful outcome is a manageable system for distinct credentials, protected access and recovery. It is not winning an argument about browsers versus apps.




