ScreenConnect Shield
All articles
Basics 7 min read

Password Managers, Explained for Non-Techies

Why writing passwords in a notebook is fine — but a password manager is better. And how to actually start.

A password manager is an encrypted notebook that only opens for you. That's it. Once you understand that, the rest is straightforward.

Why password reuse is the real threat

The #1 way personal accounts get stolen isn't sophisticated hacking — it's *credential stuffing*. Attackers take a username/password list leaked from one site (Dropbox in 2012, LinkedIn in 2016, Ticketmaster in 2024) and try those same credentials on hundreds of other sites. If you reused that password, every account is compromised. You can check whether your own email appears in a known breach at Have I Been Pwned, which indexes over 12 billion leaked accounts.

The fix is having a different, random password for every site. No human can remember 200 passwords — so let software do it.

What a password manager actually does

A password manager stores your logins in a vault encrypted with one *master password* (and ideally a hardware key). When you visit a site, it auto-fills the right credentials. When you sign up somewhere new, it generates a 20+ character random password you never have to memorize. The NIST Digital Identity Guidelines (SP 800-63B) now explicitly recommend long, machine-generated passwords over short complex ones.

Getting started in 3 steps

  1. Pick a password manager. Reputable open-source and audited options include Bitwarden, 1Password, and Proton Pass. All support phones, browsers, and desktop.
  2. Create one strong master password. Use a sentence you'd never write anywhere else — for example, three or four random words: river cactus piano grit. The EFF diceware wordlist is the gold standard for generating these.
  3. Turn on two-factor authentication on the password manager itself and on your email account. Use an *authenticator app* like Aegis (Android) or Raivo / 2FAS (iOS), not SMS — see CISA's MFA guidance on why SMS is the weakest factor.

Common worries, answered

  • *"What if I forget the master password?"* Most managers offer an emergency recovery kit (printable code). Store it physically — a fireproof box or with a trusted family member.
  • *"Isn't storing everything in one place risky?"* Vaults are encrypted on your device before they reach the manager's servers. Even if Bitwarden or 1Password were breached, attackers would still need your master password to decrypt anything.
  • *"Should I trust my browser's autofill?"* It's better than reuse, but browser vaults don't enforce 2FA, sync poorly across platforms, and unlock automatically when your OS user is logged in. A dedicated password manager adds real friction for attackers.

The 10-minute upgrade

Install a password manager today, then over the next week move your *top five* accounts (email, bank, primary social, work, cloud storage) into it with newly generated passwords. That alone closes the door on 95% of personal credential attacks.

Learn more & verify

Authoritative sources used in this article — open in a new tab.

Have a suspicious link? Don't click it.

Paste it into the ScreenConnect Shield Link Scanner for an instant safety verdict.

Scan a link