The real reason password managers are back in the spotlight
Password managers are having a moment — but not a comfortable one. The tools designed to protect your most sensitive credentials have themselves become targets, and several high-profile incidents have forced millions of users to ask a question the industry would rather they didn't: who is actually protecting the protectors?
The LastPass breach of 2022 remains the clearest wake-up call. Attackers exfiltrated encrypted password vaults along with unencrypted metadata — usernames, email addresses, billing details, and URLs. The encryption held, but the incident exposed how much sensitive context sits outside the vault itself. LastPass's delayed disclosure and fragmented communication compounded the damage, demonstrating that a vendor's breach response matters as much as its encryption architecture.
That incident didn't kill the password manager market. It accelerated its maturation. Competing products gained users rapidly, independent security audits became a selling point rather than a footnote, and open-source alternatives like Bitwarden attracted users who wanted to verify security claims rather than trust them. The conversation shifted — briefly — toward architecture, zero-knowledge design, and what "secure by design" actually means when a vendor's servers are compromised.
By 2026, the threat landscape has moved faster than most mainstream coverage acknowledges. Credential stuffing attacks, phishing-resistant authentication, and passkey adoption have all reshaped what a password manager needs to do and what risks it introduces. Yet most "best password manager" roundups still lead with feature comparisons: browser extension quality, cross-device sync, price per year.
Those features matter. But they are secondary to the question of vendor trustworthiness — specifically, the security track record, third-party audit frequency, transparency reports, and how a company has handled past failures. A credential management tool with polished autofill and a poor breach history is a liability dressed as a convenience. Choosing one without examining that history is the digital equivalent of storing your house keys with someone you've never bothered to vet.
What expert testing actually reveals — and what it glosses over
ZDNET's password manager testing process is more rigorous than most people assume. Reviewers spend hours on comparative research, pull data from vendor listings, independent review sites, and real customer feedback, then synthesize findings across multiple products before making a recommendation. That methodology beats a quick screenshot tour by a wide margin.
But rigorous is not the same as complete.
The testing frameworks used by major tech publications evaluate what is easy to measure: autofill accuracy, cross-device sync, two-factor authentication options, browser extension reliability, and pricing tiers. These are legitimate criteria. A password manager that fumbles autofill on banking sites is genuinely worse than one that handles it cleanly. Expert reviewers catch those failures, and that matters.
What the testing rarely simulates is the scenario that actually keeps users up at night. What happens when you forget your master password and your recovery options fail? What happens if the company behind your vault gets acquired, shuts down, or suffers a breach serious enough to force a full data migration? How painful is the export process when you decide to switch? These are not edge cases — LastPass users lived through a version of this stress test in 2022 when the company disclosed a major breach affecting encrypted vault data. No pre-breach review predicted the post-breach chaos of migrating credentials under pressure.
The gap between "expert recommended" and "right for your specific threat model" is real and routinely underacknowledged in roundup articles. A security-conscious journalist working from home has different exposure than a small business owner managing shared credentials across a team, who has different needs than someone whose primary concern is surviving a vendor failure with their data intact. A single ranked list cannot serve all three equally.
Expert testing tells you which password managers work well under normal conditions. It tells you almost nothing about how a product — or its company — behaves when things go wrong. That distinction is where most people's password manager decisions quietly go sideways.
The trust architecture most reviews never explain
Zero-knowledge encryption is the foundational promise that separates reputable password managers from simple cloud storage with a login screen. Under a true zero-knowledge architecture, your passwords are encrypted and decrypted locally on your device, using a key derived from your master password. The vendor's servers receive only ciphertext — scrambled data they cannot read, even under a court order or during a breach. That promise sounds simple. The implementation is not.
Bitwarden publishes its entire client and server codebase as open source. Any security researcher, anywhere, can audit exactly how the encryption pipeline works, where the keys are generated, and whether the zero-knowledge claim holds up in practice. 1Password and Dashlane operate on closed-source clients. Their security rests on vendor assertions and periodic third-party audits — which is a meaningfully different level of verifiability. That distinction rarely appears in feature comparison tables, which prioritize autofill speed and browser extension ratings over cryptographic transparency.
Third-party audits compound the problem. A security audit is a snapshot of one specific version of a codebase at one specific moment. Password managers ship continuous updates — UI changes, sync engine rewrites, new sharing features — and each update introduces new attack surface. An audit completed in 2021 tells you almost nothing about a product running in 2026. When evaluating any password manager's security credentials, the questions to ask are specific: Who conducted the audit, what was its scope, which version was reviewed, and when was it published? Some vendors answer all four clearly. Others bury a PDF from three years ago on a compliance page and treat it as permanent proof of trustworthiness.
Credential management security ultimately depends on whether you can verify the claims a company makes about its own product. Open-source code makes verification possible. Frequent, scoped, publicly published audits make it practical. Everything else — dark web monitoring, emergency access, travel mode — is a feature layer sitting on top of a trust foundation that most reviews never ask you to inspect.
Free vs. paid: The trade-off nobody is being straight about
Most major password managers have quietly narrowed their free tiers over the past few years. LastPass gutted its free plan in 2021, forcing users to choose between mobile-only or desktop-only access — a restriction that effectively pushed anyone living across devices toward a paid subscription. That pattern has become the industry playbook.
The "best free password manager" framing plastered across review roundups papers over a real problem: free plans routinely strip out the features that make a credential manager genuinely useful. Secure vault sharing, emergency access for trusted contacts, dark web breach monitoring, and priority support are almost universally paywalled. What you typically get for free is basic password storage and autofill — the minimum viable product designed to hook you, not protect you.
For a single user with modest needs, that trade-off might be acceptable. The math changes fast for anyone else. Bitwarden, widely praised as the strongest free option, charges $10 per year for its individual premium plan — reasonable by any measure. But its family plan runs $40 per year for up to six users. Dashlane's premium tier sits at $4.99 per month per person. 1Password charges $4.99 per month for individuals and $7.99 per month for families covering five users. A small business putting ten employees on 1Password Teams pays $19.95 per month minimum.
None of those numbers are outrageous in isolation. Stacked across a team or a household, they add up to a recurring line item that top-10 listicles never model out. A small business owner comparing password management options on the basis of a "Best Of" article is getting a feature checklist, not a cost-of-ownership picture.
The accessibility gap is real. Restricting cross-device sync, breach alerts, and secure sharing to paid tiers means the users who most need comprehensive credential security — people who can't afford to recover from identity theft — are the ones most likely to be running an under-equipped free plan. Free tiers increasingly function as conversion funnels, not genuine security tools.
Passkeys and the looming question: Are password managers already obsolete?
Apple, Google, and Microsoft didn't just endorse passkeys — they built passkey support directly into their operating systems and browsers, making the FIDO2-based authentication standard a default rather than an opt-in experiment. Apple Keychain stores passkeys natively. Google Password Manager does the same across Android and Chrome. The infrastructure for a passwordless internet already exists at the platform level, and that reality forces a straightforward question: why pay for a third-party credential manager at all?
The honest answer is that the transition is fractured. Thousands of websites and enterprise applications still require traditional passwords, two-factor codes, and stored form data. The average user juggles accounts across services that span multiple years of varying security practices. Passkey adoption among websites remains uneven — major platforms like GitHub, PayPal, and Shopify support them, but the broader web has not caught up. A genuinely passwordless daily experience for most people is still years away.
Password manager vendors know this and are repositioning fast. Dashlane, 1Password, and Bitwarden have all added passkey storage and sync capabilities, framing their products as identity hubs rather than simple password vaults. 1Password launched its passkey management feature and built cross-device passkey sync before Apple and Google extended theirs across competing ecosystems — a deliberate effort to capture users who live across multiple platforms and can't rely on a single OS vendor.
The repositioning makes sense commercially, but it papers over a genuine category problem. If Apple Keychain or Google Password Manager eventually handles passkeys, secure notes, payment cards, and identity verification seamlessly across all devices, the value proposition of a standalone password manager compresses significantly.
For now, that compression hasn't happened. Users who operate across Windows, macOS, Android, and iOS simultaneously — a common reality for professionals — still need cross-platform credential sync that Apple and Google don't fully provide for each other's ecosystems. Password managers fill that gap. The category isn't obsolete, but it is in genuine transition, and the vendors who survive will be the ones users trust to hold not just passwords, but the next generation of phishing-resistant credentials that replace them.
How to actually pick the right one for you in 2026
Start by ignoring every "best overall" list. Those rankings optimize for features reviewers can screenshot — autofill speed, browser extension polish, interface design. None of those things tell you whether the company holding your credentials deserves that responsibility.
Three criteria actually matter: vendor transparency, audit history, and data portability.
Transparency means you can read a clear, public explanation of how the company's zero-knowledge encryption works, who has access to what, and what happens to your vault if the company gets acquired or goes under. If that information requires a support ticket to find, treat it as a warning.
Audit history means independent third parties have tested the product and the results are published — not summarized in a press release, but actually published. Check when the most recent audit happened. A security audit from 2021 on software that ships updates monthly is not a meaningful guarantee.
Data portability is the test most people skip. Before you commit to any password management tool, export your vault. Do it on day one of your free trial. If the export fails, produces a format nothing else can read, or buries the option four menus deep, the company has already told you how they view your relationship: as a retention strategy, not a security partnership.
Your threat model shapes everything else. A journalist protecting source communications needs a credential manager with strong local storage options and minimal cloud exposure. A small business owner managing shared team access needs granular permission controls and a clear breach-notification policy. A casual user securing personal accounts needs something they will actually use every day without friction. No single product wins all three categories, and pretending otherwise is how people end up with tools that don't fit their real lives.
Pick the password vault that publishes its audits, exports your data cleanly, and matches how you actually work. Everything else is marketing.
Originally published at Newzlet.
Top comments (0)