The old advice — "never save passwords in your browser" — is out of date. Apple's and Google's built-in password managers are now genuinely good, and if your whole digital life lives in one ecosystem, they're enough. Mix platforms (iPhone plus Windows, work Chrome plus home Safari — most of us), and a dedicated manager wins, with excellent free options like Bitwarden and Proton Pass. Passkeys aren't a third competitor: turn them on wherever offered, and let your manager hold everything else. Full decision framework and a 15-minute migration plan below.

The average person now juggles well over 100 online accounts, and every reused password among them is a domino waiting for one breach to knock the lot down. The good news is that 2026's answer to "how should I store passwords" is clearer than it's ever been — and cheaper, with genuinely great free options. The confusing part is that three different things now compete for the job: your browser's built-in manager, dedicated password managers, and the new kid, passkeys. Here's the honest three-way comparison, without the affiliate-link thumb on the scale.

The old advice is dead: browser managers got good

For years, "browser password storage is insecure" was standard tech advice. It's no longer fair. Apple's Passwords app is now a standalone, end-to-end encrypted manager with passkey support and secure sharing. Google Password Manager has on-device encryption, breach alerts and passkey storage. Microsoft's Edge syncing is solid. If you live 100% inside one ecosystem — all-Apple with Safari, or all-Google with Chrome and Android — the built-in option is genuinely good, free, and infinitely better than reusing "Winter2026!" everywhere.

So why does anyone pay for a dedicated manager? One word: ecosystems. Almost nobody actually lives in one. The moment your life spans an iPhone and a Windows PC, or work Chrome and personal Safari, browser-based storage turns into a mess of half-synced silos — and that's where dedicated managers earn their keep.

Where dedicated managers still win

  • They work everywhere. One vault across every browser, OS and phone you'll ever own — no ecosystem lock-in, no "which browser saved that one?"

  • Better password generation. Custom lengths, passphrases, site-specific rules — versus the browser's take-it-or-leave-it string.

  • They hold more than passwords. Secure notes, cards, IDs, two-factor codes, and passkeys — one encrypted home for the lot.

  • Breach monitoring. Alerts when a site you use leaks, plus password-health reports that surface your reused and weak logins.

  • Safe sharing and recovery. Share the Netflix login with family properly (not via text message), and set emergency access so your accounts aren't lost with you.

And the kicker: this no longer costs money. Bitwarden's and Proton Pass's free tiers include unlimited passwords with cross-device sync and strong encryption — the paid tiers add nice-to-haves (advanced 2FA options, dark-web monitoring, family plans), not the essentials. There is no budget excuse left.

Passkeys: the future that's already here

Passkeys are the genuinely new thing: instead of a secret you type (and can be tricked into typing on a fake site), a passkey is a cryptographic key pair — your device proves it's you with a fingerprint or face, and there's no password to phish, leak or reuse. They're built on the FIDO2/WebAuthn standards, browser support is now mainstream, and adoption is accelerating fast because they kill the number-one attack (phishing) stone dead — which matters more than ever now that AI-written phishing messages are frighteningly convincing.

Two practical notes. First, passkeys aren't universal yet — a fraction of your 100+ accounts offer them, so they can't replace your whole setup for years. Second, they're not a rival to password managers: modern managers (and the browser ones) store passkeys right alongside passwords, and the industry is actively making them portable between platforms. The correct 2026 mindset is not "passkeys vs manager" — it's passkeys wherever offered, manager for everything else, with the manager as the bridge through the long transition.

The decision table

Your situation Your best setup
100% one ecosystem (all-Apple or all-Google), casual needs Built-in browser/OS manager + passkeys where offered. Free, good, done.
Mixed devices — iPhone + Windows, multiple browsers (most people) Free dedicated manager (Bitwarden / Proton Pass class) + passkeys where offered.
Family logins, shared accounts, "I'm the household IT person" Paid family plan of a dedicated manager — sharing and recovery features pay for themselves.
High-value accounts: business, crypto, big platforms Dedicated manager + hardware-grade 2FA + passkeys everywhere possible.
Currently reusing one password everywhere Any of the above, today. The gap between "nothing" and "anything" is the biggest security jump on this page.

The gamer angle: your Steam account is a target

Worth a Glitchory-specific word, because gaming accounts are among the most stolen credentials on the internet — a Steam library is years of money, PSN and Xbox accounts carry stored cards, and rare skins resell. The attack is almost never a hacker "breaking in"; it's you reusing a password that leaked from some forum in 2019, or typing it into a fake "free skins" login page. The fix is exactly this article: unique passwords per account (manager's job), passkeys or app-based 2FA on Steam, PlayStation, Xbox and Epic, and the healthy paranoia we preach in our Windows security guide — no antivirus saves an account you hand over yourself. (And no, a VPN doesn't protect passwords — different tool, different job.)

The 15-minute migration plan

Switching sounds like a weekend job; it's a coffee break:

  • Minutes 1–3: pick your tool (decision table above) and install it plus its browser extension and phone app.

  • Minutes 3–5: create a master password that's long and memorable — a four-word passphrase beats "P@ssw0rd123" by miles. This is now the only password you memorise.

  • Minutes 5–8: export your saved passwords from the browser (Chrome: Settings › Passwords › export) and import the file into the manager. Delete the export file afterwards — it's plain text.

  • Minutes 8–10: turn off the browser's own save-and-autofill so the two stop fighting, and let the manager's extension take over.

  • Minutes 10–15: save the recovery kit somewhere offline, switch on the manager's 2FA, and let its health report queue up your worst reused passwords to fix — a few per week is plenty.

From then on the manager does the remembering, generates a fresh strong password every time you sign up somewhere, and offers passkeys as sites add them. Future you, mid-breach-headline, will be very calm.

The honest downsides (yes, there are some)

Fair play demands the counterargument. A manager is one basket for many eggs — mitigated by strong encryption, your master passphrase and 2FA, but real; pick a reputable, audited provider and treat that master passphrase like the crown jewels. Losing the master password can genuinely lock you out — hence the recovery kit step above; do not skip it. And autofill convenience can breed complacency — a manager refusing to autofill on a look-alike site is actually a phishing warning, not a bug, so notice it. None of these outweigh the alternative: the "system" of reused passwords in your head has all the same eggs in a much flimsier basket, pre-cracked by whichever of your 100 sites leaks next.

Frequently asked questions

Is it safe to save passwords in Chrome or Safari in 2026?

Far safer than it used to be — Apple's Passwords app and Google Password Manager now offer strong encryption, breach alerts and passkey support. They're a solid choice if you live entirely in one ecosystem; a dedicated manager wins once your devices and browsers mix.

Do I need a password manager if passkeys exist?

Yes, for now and years to come. Only a fraction of sites offer passkeys, so you'll hold passwords for the long tail regardless — and modern managers store passkeys alongside passwords, making them the bridge through the transition rather than a casualty of it.

What's the best free password manager?

Bitwarden and Proton Pass both offer genuinely complete free tiers: unlimited passwords, cross-device sync and strong encryption. Paid upgrades add extras like advanced 2FA and dark-web monitoring, but the free versions cover the essentials.

What are passkeys and are they safer than passwords?

Passkeys replace typed secrets with device-held cryptographic keys unlocked by your fingerprint or face. Built on FIDO2/WebAuthn, they can't be phished, leaked in a site breach, or reused — making them meaningfully safer than any password. Turn them on wherever offered.

What happens if I forget my master password?

Depending on the manager, recovery ranges from a saved recovery kit or code to, in strict zero-knowledge setups, permanent lockout. Create the recovery kit during setup and store it offline — it's the one non-negotiable step.

Is one password manager account risky — a single point of failure?

It concentrates risk, but behind strong encryption, a long master passphrase and 2FA — a far tougher target than 100 reused passwords already circulating in old breach dumps. Choose an audited, reputable provider and the basket is worth its eggs.