What a password manager can and cannot solve

A password manager can help you store credentials and use different passwords for different services without relying on memory. But it does not replace the security measures of the sites you access, or decide for you what to do if you lose a device, forget your master password or someone gains control of your account. The app is one link in a chain: the sign-in method, authorized devices, recovery options and the way data is synchronized all matter too. Thinking about the product as part of this wider chain helps set realistic expectations. A manager can make some routines easier, but it cannot make every account or device secure on its own.

It is useful to distinguish protection of stored credentials from protection of the password manager account. An encrypted vault may make it harder for another person to read your data if they obtain a copy, but that alone does not show that the sign-in process, recovery options or provider apps are suitable for your needs. NIST’s authentication guidance describes authentication as the process of checking that the person seeking access controls the authenticators associated with an identity. Its guidelines are intended for digital identity systems; they do not certify specific commercial password managers. NIST SP 800-63B.

The definitions in this glossary are therefore intended to turn technical expressions into concrete checks, not to declare a winning product. The cited sources document concepts and general recommendations; they do not compare every available manager or verify how a particular version behaves. A striking label is no substitute for an explanation of the mechanism, its exceptions and the consequences for someone who loses access. When comparing products, look for information that answers what happens in ordinary use and in less convenient situations. That is more useful than relying on a feature name alone.

Vault, encryption, master password and zero knowledge

A vault is the digital space where items such as usernames and passwords are organized and, depending on the service, other data may be stored. Ask what kinds of information it accepts, how it is locked and what happens to an open session if a device is lost. The term does not guarantee that every item is encrypted in the same way, that all metadata is protected or that the content exists only on one device. Those details depend on the provider’s architecture and documentation. It is worth checking whether the provider describes protection for attachments or other stored information as well as login credentials, rather than assuming that the word “vault” covers everything.

Encryption transforms data so it cannot be read without the necessary cryptographic material. The phrase “end-to-end encryption” generally indicates that data is protected in a way that should prevent the provider from reading its content, but you should check how it is applied: before or after synchronization, on which devices and what information is excluded. A claim of “zero knowledge” should not automatically be treated as a synonym for total security either. Look for an accessible technical explanation, identify which secrets the user controls and understand what capabilities the service retains to operate or recover the account. The name of a technique does not, by itself, describe every part of the system or every exception.

The master password—also called a master key or master password in some products—is the secret that can unlock the vault or take part in deriving the keys that protect it. It is not simply another password in the list: losing it can have different consequences from losing the password to a web account. Before choosing a service, ask whether the provider can reset it, whether a recovery phrase exists and what data is lost or remains available in each scenario. A convenient reset process and the possibility of a third party intervening can involve different trade-offs. Do not assume that recovery is always possible without data loss; the provider’s documented process is what matters.

Multifactor authentication and passkeys

Multifactor authentication (MFA) requires more than one factor to verify identity. In practical terms, factors can be based on something you know, something you have or a biometric characteristic. A second step can reduce dependence on an exposed password, but different methods do not provide the same experience or properties against attacks. CISA recommends adopting MFA as a way to add protection beyond a password; that does not mean turning on any option eliminates risk. Consider how the method works in the situations you actually encounter, including when a device is unavailable. CISA: More than a Password.

When comparing managers, distinguish between MFA used to open the manager account and MFA that the product stores or helps you use with other services. Ask which methods it supports, whether recovery codes are available and what happens if you lose your phone or authentication device. OWASP’s authentication guidance addresses topics such as sign-in and secure recovery separately; it is a design reference, not a certification of any particular provider. This distinction matters because a manager may support one set of methods for protecting its own account and offer different capabilities for credentials used elsewhere. OWASP Authentication Cheat Sheet.

Passkeys are sign-in credentials that let you authenticate without typing a traditional password, using compatible capabilities of the device, platform and service. They are not simply a password stored in a vault. Google’s documentation describes their use and lists support in Android and Chrome, but practical availability depends on the environment, the service and how the credential is stored or synchronized. Ask whether the manager can store or synchronize passkeys, which platforms support that feature and what alternative remains if you change ecosystems. Compatibility should be checked for your own devices and services rather than assumed from the feature name. Google: Passkeys and supported environments.

Recovery, synchronization and emergency access

Recovery describes the options available when you cannot unlock the vault or sign in. It may involve recovery codes, previously authorized devices, help from a contact or a process managed by the provider; these are not equivalent. Find out whether recovery restores access to the same data, whether another device must remain available and whether the process changes the privacy or trust model. If the service does not explain the procedure clearly enough, do not assume customer support can return the contents of your vault. A concise, specific account of the steps and consequences is more useful than a general promise that recovery is available.

Synchronization makes information available on more than one device; it also raises questions about what is transmitted, where it is processed and how synchronized copies are protected. Do not confuse “synchronizes” with “there is a recoverable backup.” Ask what happens if you delete an item on one device, whether changes propagate and how you can export or preserve your data. NIST SP 800-63B includes considerations for syncable authenticators, but it is aimed at credential service providers and authentication systems; it is not an assessment of a particular password manager. The distinction is important: guidance about a category of authenticators does not establish how a commercial product implements synchronization. NIST SP 800-63B, appendix on syncable authenticators.

Emergency access usually describes mechanisms that let another person obtain access under certain conditions. The label alone does not tell you who can request access, how long the wait is, whether the user can reject the request or what data is exposed. Read the entire process from both sides and consider what could happen after loss of capacity, a dispute or a change in the relationship. If you need this feature, check whether it can be limited to selected items and revoked without relying on a contact who may no longer be reachable. Understand the conditions before relying on the arrangement, rather than discovering them during an emergency.

Turn definitions into comparison criteria

A useful comparison starts with your own situation: the operating systems and browsers you use, how many devices you have, whether you need to share credentials and how comfortable you are depending on a cloud account. Then compare what the provider documents, not just the names of its features. If it says data is encrypted before synchronization, look for what information is excluded and how the key is managed. If it advertises recovery, check whether the process preserves the data and what authority the provider or designated contact has. Written details make it easier to compare like with like instead of treating similar labels as proof of identical behavior.

To reduce the comparison to verifiable questions, use this checklist:

  • What data does the vault store, and which categories are outside the described encryption?
  • How do I unlock the account, and which MFA or passkey options are available on my devices?
  • What recovery options exist, and what happens to the data in each case?
  • Can I export my credentials in a usable format and close the account without losing control of the data?
  • Which platforms, browsers and functions do I need, and where are their limitations documented?
  • What does the plan I need cost in my market, and what conditions change if I stop paying?

Checklist before choosing

Before signing up, confirm actual compatibility with the devices and browsers you use: a general availability page does not guarantee that every feature is present in every version. Google’s passkey documentation, for example, shows why it is sensible to check the platform and environment rather than treat compatibility as universal. If you depend on a particular operating system, also check what happens with extensions, biometric unlocking and cross-platform synchronization. Product pages and help documentation may describe different levels of support, so look for details that match your own setup.

Review export and exit options as carefully as sign-up. Find out whether you can export without losing important fields, whether the resulting file is readable outside the manager and how to delete it safely afterward. Check pricing terms for the country where you live, and distinguish included features from device limits and family or business plans. The documentation of the cited sources does not establish prices or availability for commercial products; it would not be appropriate to infer them or present a price as current without a provider source and an observation date. Treat price and feature availability as details to verify directly.

As a final decision, prioritize the requirements that would affect you most if they failed: losing the master password, changing phones, the service becoming unavailable or needing to share access. Compare written, up-to-date answers rather than vague promises. A manager can make it easier to maintain distinct credentials and organize access, but your choice should also account for recovery, supported platforms and your ability to leave the service. The best comparison is not an abstract score: it is knowing what happens in the cases that genuinely concern you.