In short. The choice matters less than actually using one, and the real differences are narrower than the comparisons suggest: where the vault lives, whether the code has been audited, and what happens if you lose the master key. That last one is the question most people skip.
You already have a password manager — in your browser, on your phone, in your Google or Apple account. Most people searching for one are not choosing between products; they are trying to find the one they have: where it lives, how to reveal a saved password, and what to do when it saved the wrong thing. Here is where each one hides, and why it matters even if your browser "remembers passwords anyway".
What a password manager is, and why it is not the same as "the browser remembered it"
A password manager is a vault encrypted under one master key. You remember one password; it remembers the rest. The difference from ordinary "save password in browser" is not convenience — it is what encrypts the vault and what happens when somebody gets your device.
Browser storage was for years encrypted with an operating-system key: anyone who unlocked your computer could read every password in plain text in about three clicks. Chrome, Firefox and Edge can now lock the list behind a master password or a fingerprint, but it is frequently off by default. A dedicated manager keeps the vault closed and hands over nothing until the master key is entered.
The distinction is simple: "the browser remembered it" protects you from someone looking over your shoulder. A password manager protects you from someone holding your laptop.

Where the password manager is in each browser
| Browser | How to open it |
|---|---|
| Google Chrome | chrome://password-manager/passwords, or Settings → Autofill → Password Manager |
| Mozilla Firefox | about:logins, or Settings → Privacy & Security → Saved Logins |
| Microsoft Edge | edge://wallet/passwords, or Settings → Profiles → Passwords |
| Safari (macOS) | Settings → Passwords; on iOS, Settings → Passwords |
| Opera | opera://settings/passwords |
In every case, revealing the password rather than the dots requires your device account password or a fingerprint. If it never asks, the vault protection is switched off — and that is the first thing worth fixing.
Where it is on a phone
On Android the passwords live in the Google account rather than the browser: Settings → Google → Autofill → Google Password Manager. The same list is at passwords.google.com on a computer — one vault, two doors.
On iPhone and iPad it is Settings → Passwords, with a dedicated Passwords app on recent iOS versions. The vault is shared between Safari and apps and syncs through iCloud Keychain.
A common confusion: someone saves a password in Chrome on a computer, looks for it in mobile Chrome, and does not find it. The cause is almost always sync being off, or being signed into a different Google account.

How to reveal a saved password
- Open the manager using the address from the table above.
- Find the site in the list — there is usually a search box at the top.
- Click the eye icon or "Show".
- Confirm with your device password, PIN or fingerprint.
Why a manager beats inventing passwords yourself
Because people cannot invent randomness. Invented passwords are built from a name, a date, a keyboard run, or a word with substitutions like a→@ and o→0. Every one of those patterns is in the cracking lists, which is why Password2024! computes to about 85 bits of entropy and is guessed instantly.
The second reason matters more: a manager removes the need to reuse. One password on two sites means a breach of one is a breach of both — stolen email-and-password pairs are replayed against hundreds of services automatically, and it takes minutes.
You can measure any specific password in the password generator: it shows entropy in bits and guessing time across four attacker models, and the analysis runs in your browser rather than on a server.

Which manager to choose
We do not sell a password manager and are not paid for recommendations, so the answer is dull: almost any will do if it meets three conditions.
- Client-side encryption. The service must not be able to read your vault. It is usually described as zero-knowledge.
- Export. Being able to take everything out as a file is your guarantee against a service closing or raising its price.
- Open or audited code. Not proof of safety, but evidence that somebody checked the claims.
The built-in managers from Google and Apple mostly meet these and cost nothing. Their weakness is the ecosystem: moving between Android and iPhone, or between browsers, becomes awkward exactly when you need it.
Cleaning up the passwords you already have
- Find the reuse. Google and Apple flag it themselves — the manager has a checkup section marking repeated and weak passwords.
- Start with email. The mailbox restores access to everything else, so its password is changed first and made longest.
- Then money. Banking, marketplaces with a stored card, government portals.
- The rest as you go. Do not try to change two hundred passwords in an evening; change the one whose site you just opened.

The master password: the one you must remember
The master key cannot be recovered — that is what zero-knowledge means. So it has to be both strong and memorable, which is exactly the case a passphrase is for: four to six random words give 52–78 bits of entropy and are far easier to hold in your head than a string of symbols.
The words must be picked by a program, not by you. A phrase a person invents is almost always a quotation, a song line or a set expression — that is, predictable. The same generator produces one in passphrase mode.
Frequently asked questions
Is it safe to keep passwords in a browser?
Safer than notes or a file on the desktop, and worse than a dedicated manager with a master password. The main risk is access to an unlocked device: if the vault is not behind its own key, every password is a few clicks away.
What happens if I forget the master password?
In a properly built manager, nothing good: the vault is not recoverable because the service holds no key. Which is why the master password is written on paper and kept where you keep documents. That is not paranoia — it is the only backup that exists.
Do I need a manager if two-factor authentication is on everywhere?
Yes. A second factor protects the login; it does not protect against the same password working on a service that has no second factor. They are separate layers and do not substitute for each other.
Is a paid manager worth it?
Not necessarily. Free options with client-side encryption are sufficient. Paying makes sense for family or team sharing, longer history and support — but not for "stronger encryption", which does not get stronger with money.
In short
- You already have a password manager — in the browser and in your phone account; the question is usually where it is, not which to buy.
- "The browser remembered it" protects against a glance over your shoulder; a manager with a master password protects against someone holding the device.
- The real benefit is not convenience — it is that passwords stop repeating.
- Make the master password a passphrase of random words and write it on paper.
- Start the cleanup with email, then banking and government services, then the rest as you go.