SPC Servis PC Brno

Password Manager: How to Choose One and Stop Reusing a Single Password

One favourite password in three variants everywhere isn't a system, it's waiting for trouble. Here's which password manager makes sense at home and for freelancers, and how to make the switch in one afternoon.

Ing. Miroslav Jaroš updated August 15, 2026 11 min read
Password Manager: How to Choose One and Stop Reusing a Single Password

Most people don’t have twenty passwords. They have one favourite in three variants — the base, the base with an exclamation mark and the base with a year — scattered across twenty services. It works for years, right up until the password leaks from the weakest link: a small e-shop, a forum, a loyalty programme. Within hours, bots are trying it on your e-mail, your bank and your social accounts.

A password manager cuts that chain. It holds a different long password for every service, and you only have to remember one. The question isn’t whether you need one, but which to pick and how to see the switch through to the end.

Short answer: For a household that wants the least possible hassle, the most sensible starting point is Bitwarden — a fully featured free tier, sync between phone and computer, Czech localisation. If you don’t want your passwords in any cloud, reach for KeePassXC (the vault is an ordinary file you keep yourself). If you want the smoothest apps and family sharing and don’t mind a subscription, pick 1Password. More important than the brand, though, are three steps: a strong master password in the form of a passphrase, two-factor authentication on the vault itself, and a migration you finish properly — move the passwords out of the browser, delete them there and turn saving off.

Why one password everywhere eventually fails

Attackers today don’t guess passwords at your bank. They wait for some weakly secured service to lose its user database, and then bots try the leaked e-mail + password combinations en masse on the big sites. It’s called credential stuffing, and it’s why a “strong” password used everywhere isn’t strong — its resilience equals that of the worst-secured site you ever typed it into.

Variants don’t help. Patterns like swapping the year, an exclamation mark at the end or a letter replaced by a digit come as standard equipment in attack tools. And your e-mail is the master key: whoever takes it over resets access to everything else through “forgot password”. What to do once that has already happened is covered in our article hacked e-mail: what to do — and frankly, it’s a far more laborious read than this piece on prevention.

The second route to your passwords runs through fake websites. Here too a password manager helps in practical terms: it only fills in logins on the domain the password belongs to. On a bank lookalike whose address differs by one letter it simply leaves the form empty — often the first and only warning you get. How to spot fraudulent messages is covered in our article phishing: how to spot it.

Passwords in the browser: better than nothing, but there are limits

Chrome, Edge and Firefox all save, generate and sync passwords these days. For plenty of people that’s a first step in the right direction, and we’re certainly not dismissing it. But it has limits that rarely get discussed.

Passwords in the browserStandalone manager
Pricefreefree to subscription
Worksonly in that browser and its ecosystemin every browser, in apps and on your phone
Lockingunlocked profile = unlocked passwordsits own master password, vault locks itself
Family sharingpractically notshared folders, emergency access
What it holdsloginsplus backup codes, PINs, notes, cards, passkeys
Resilience against browser malwarelower — everything lives inside the browserhigher — the vault sits outside

That last row matters. Whoever takes over your browser profile — through a malicious extension, malware, or simply by sitting down at an unlocked computer — reaches the passwords in it as well. That innocuous-looking extensions are a real way to lose your passwords is something we described in our article dangerous browser extensions. A standalone manager locks with its own password, and locks itself after a few minutes of inactivity — one more wall for an attacker to climb.

Browser passwords make sense as a temporary solution for one person with non-critical accounts. As soon as banking, company access or household sharing is involved, it pays to take the next step.

Bitwarden, KeePassXC, 1Password: three temperaments

There’s no point comparing twenty products. For a household or a freelancer, the choice in practice comes down to three names with three different temperaments.

Bitwarden is the most sensible first choice. The free version isn’t a taster — it handles an unlimited number of passwords and syncs between computer, phone and tablet. It’s open source, it speaks Czech, and the paid family plan adds shared collections (home wi-fi, streaming services, the energy supplier account) and emergency access for someone close to you. If you don’t know, start here.

KeePassXC is the choice for anyone who doesn’t want passwords in any cloud. The vault is a single encrypted file on your own disk, the program is free and works entirely offline. The price of independence: you handle syncing between devices yourself (carrying the file across or putting it on your own storage), and it’s noticeably less convenient. Excellent for the technically confident, frustrating for the rest of the family.

1Password is the most polished, but paid only. The subscription buys you the nicest apps, sophisticated family sharing for several members and monitoring for leaked passwords. If the whole household is meant to use the manager, including those who “aren’t computer people”, 1Password’s comfort genuinely decides whether they stick with it.

All three now store passkeys alongside passwords — passwordless sign-in that the big services are gradually rolling out. A manager bought this year will make that transition with you; you won’t be starting over in a year’s time.

The master password: the only one you have to learn

The whole system rests on a single password, so it deserves more than a minute’s thought. What works best is a passphrase of four or five unrelated words — long, yet memorable and typeable even on a phone. It must not be a quotation, your children’s names, or anything you’ve already used somewhere.

Add two safeguards:

  1. Two-factor authentication on the vault itself, via an app on your phone. Even if someone watches you type the master password, they can’t get into the vault without the second factor.
  2. A recovery sheet on paper: the master password and backup codes printed out and kept at home away from the computer — and ideally a second copy elsewhere, at your parents’ place or in a locked drawer at work. Same logic as with backups following the 3-2-1 rule: one copy is no copy.

Paper isn’t a weakness, it’s an insurance policy. The provider doesn’t know your master password and can’t recover it — which is precisely why you can trust it with the vault. When attackers stole LastPass’s vault backups in 2022, the only thing standing between them and the contents, for each user, was the strength of that user’s master password. Weak passwords fell, strong passphrases held. That’s the whole lesson in one sentence.

Moving your passwords: a plan for one afternoon

The most common reason a switch fails isn’t the technology, it’s not finishing it. A manager installed “just to try” alongside password saving still switched on in the browser creates two sets of records, and after a month people drift back to their old habits. The right procedure:

  1. Create the vault and set up a master password + two-factor authentication. Write out the recovery sheet right now, not “later”.
  2. Install the browser extension and the phone app. A manager that doesn’t fill things in for you is a manager nobody will use.
  3. Export your existing passwords. In Chrome via Settings → Autofill and passwords → Google Password Manager → Settings → Export passwords, in Edge via Settings → Profiles → Passwords, in Firefox via Passwords → Export Logins.
  4. Import the file into the manager and delete it immediately — including from the trash. The export is readable text; leaving it sitting in Downloads means having all your passwords in one unprotected file.
  5. Turn off password saving in the browser and clear the passwords stored there. From this moment on there is a single source of truth.
  6. Change the passwords on your five most important accounts — e-mail, bank, Google or Microsoft account, social networks. Let the manager generate long random passwords; you never need to see them, let alone memorise them. Change the rest as you go, whenever you use those accounts.

Budget two to three hours of unhurried work. And if this is exactly the task you’ve been putting off for six months, or you’re worried you’ll lock yourself out somewhere during the transfer — book it as a service: we’ll go through it with you at your home or remotely, including moving the passwords, setting up your phone and printing the recovery sheet. We bill in half-hour blocks, roughly 1,200 CZK per hour of work; full rates are in our price list. Most households have it sorted in a single session.

The most common worries — and what’s true about them

“All my eggs in one basket.” Except that basket is encrypted, locked and guarded by a second factor — whereas one password everywhere means twenty baskets with no lid. The risk doesn’t add up, it moves from places you don’t control (other people’s databases) to a place you do.

“I’ll forget the master password.” That’s what the recovery sheet is for, plus emergency access with Bitwarden or 1Password: you nominate someone close to you in advance who may request access, and unless you decline the request within a set period, the vault opens for them. Incidentally, it’s also the answer to the situation nobody wants to think about — what happens to your accounts if something happens to you.

“What if the internet or the service goes down?” The app keeps an encrypted copy of the vault on the device, so you can get to your passwords offline too. With KeePassXC, offline operation is the very essence of the solution.

“My parents will never manage it.” The opposite is true: filling in a login with one click is easier than remembering and retyping it. The hardest part is the first afternoon — which is why we offer it as a service.

For freelancers and small businesses: passwords aren’t a private matter

In a small company the password situation tends to be even starker: a hesla.xlsx spreadsheet on the shared drive, one password for e-mail, the bank and the accounting system, and a former part-timer who still knows it. A password manager with team sharing solves this systematically — everyone has their own vault, shared access lives in a common collection, and when someone leaves you remove their account rather than changing thirty passwords one at a time.

Introducing a manager is one of the seven steps described in our article securing a small company’s computers. And if you’d first like to know exactly where you stand, we’ll do an IT audit — we’ll go through accounts, passwords, backups and encryption, and you’ll get a written report with priorities; for a small company of up to roughly ten devices, indicatively from 3,600 CZK.

One password everywhere is a habit, not a decision. The decision is this afternoon — and it’s one of the few things in IT security you do once and it serves you for years.

  • #password manager
  • #Bitwarden
  • #KeePassXC
  • #1Password
  • #two-factor authentication
  • #Brno
Share:

Found this useful? More security and privacy write-ups at ithope.cz.

Call Contact