Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

What A Password Manager Actually Changes About Risk

Storing every password in one place sounds like concentrating risk, and the reason it reduces it is that reused passwords fail across every account at once.

Individual using a VPN application on a laptop at a desk in a modern office setting.
Photograph by Dan Nelson via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Putting every credential behind a single password appears to create one catastrophic point of failure. The comparison that matters is not with perfect security but with what people do instead.

Human memory forces reuse

Nobody can remember dozens of long random strings, so the practical alternatives are short passwords, predictable patterns, or the same password across many sites.

Reuse is the significant one. It links accounts together so that a failure at the least careful site becomes a failure everywhere.

A manager removes the constraint entirely. Passwords no longer need to be memorable, so they can be long and unrelated to each other.

The vault is encrypted before it leaves the device

A well-designed manager derives an encryption key from the master password on the device and encrypts the contents there.

The provider stores an encrypted blob it cannot read. A breach of their servers yields data that is useless without the master password.

Key derivation is deliberately slow, applying a costly transformation many times so that testing candidate passwords in bulk is impractical.

Autofill provides an unexpected defence

A manager fills credentials only on the address it recorded them against. A convincing imitation of a site at a different address gets nothing.

This is a stronger check than human judgement, which is examining a rendered page rather than comparing an exact string.

The corollary is that a manager silently declining to fill is information. The reflex to copy the password manually discards exactly the protection being offered.

The master password becomes the whole problem

Concentration is real. A weak master password, or one reused elsewhere, undermines everything behind it.

Second-factor protection on the account helps against remote access but not against someone with a copy of the vault file, which is why the master password must be strong in its own right.

Recovery is deliberately limited for the same reason. A provider able to restore access to a forgotten master password would necessarily have a route into the contents.

The failure modes are different, not absent

Malware capable of reading memory on an unlocked device can extract entries, which is a genuine risk that reuse does not share.

Locking timeouts, biometric prompts and separate handling of the most sensitive entries exist to narrow that window rather than close it.

The honest description is a trade: many independent moderate risks exchanged for one concentrated risk that can be defended deliberately.

Questions readers ask

What happens if I lose my phone?

If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.

Is a passkey the same as biometric login?

No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.

Data & Privacysecurityauthenticationcryptographyaccounts
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas