If you are like most American adults over 60, your relationship with online passwords is some version of the following. You have one password you really like — maybe a pet's name plus a birth year, or a favorite word with a number at the end. You use it for everything, with small variations to satisfy different sites' requirements (a capital letter here, an exclamation point there). You write the variations on a piece of paper that lives next to your computer, or you keep them in a notebook in a drawer. When a website forces you to reset a password, you sigh, grumble, and write down the new one on the same piece of paper.
This system is completely understandable. It is also one of the most dangerous things you can do online, and it is the single biggest reason older adults get hacked, have their email accounts compromised, lose money to fraudsters, or wake up to find that someone has emptied their bank account. The reason is simple. If any one of the websites you have an account on gets hacked — and dozens of major websites get hacked every year — your password ends up in a database that is sold on the criminal underground. Hackers then use that password (and small variations of it) to try to log into every other website where you might have an account. Because you reused the same password, they get into your bank account, your email, your social media, and anywhere else they can find. The chain reaction from a single password leak can be devastating.
The fix is to use a different, complex, unique password for every single account. But no human being can remember 100 different complex passwords. The fix is therefore not to remember them yourself. The fix is to use a tool that remembers them for you. That tool is called a password manager, and it is the single most important security upgrade any adult over 60 can make.
A password manager is a small piece of software that runs on your computer, your phone, or both. Its job is to store all of your passwords in an encrypted database, and to fill them in automatically when you visit a website that needs one. You log into the password manager once with one master password (the only password you ever need to remember), and from that point on, the manager handles all the others.
When you visit a website you have an account on, the password manager recognizes the site and offers to fill in your username and password. You click yes, and you are logged in. When you create a new account somewhere, the password manager offers to generate a long, random, complex password for you (something like 'gK7pQ9fH2xL4nM8w'), and stores it automatically. The next time you visit that site, the manager fills in the same complex password for you. You never need to remember it, write it down, or type it.
The encryption used by password managers is extremely strong — strong enough that even sophisticated attackers cannot crack the database without the master password. As long as your master password is strong (and you do not write it down somewhere obvious), your accounts are dramatically safer than they were when you were reusing the same password everywhere.
There are dozens of password managers on the market, but for most older adults the choice comes down to three.
Bitwarden (free or $10/year). Bitwarden is the best free password manager available. It is open-source (which means independent security researchers can verify how it works), it has been audited by major security firms, and the free version is fully featured for personal use. It works on Windows, Mac, iPhone, iPad, Android, and most web browsers. The interface is straightforward and the setup is well-documented. If you want a free password manager that you can trust, Bitwarden is the answer. The $10/year premium version adds some nice extras (file sharing, advanced two-factor authentication options) but most users do not need them.
1Password ($35/year). 1Password is the most polished and user-friendly paid option, and many people who are willing to pay a small annual fee find it worth the money. The interface is excellent, the setup is guided, the support is responsive, and the experience of using it day to day is slightly smoother than Bitwarden. If you want the easiest possible experience and you do not mind paying $35 per year, 1Password is an excellent choice.
Apple iCloud Keychain (free, Apple users only). If you use only Apple devices — iPhone, iPad, Mac — you may not need a separate password manager at all. Apple's built-in iCloud Keychain is now a fully featured password manager, integrated into Safari and other Apple apps. It generates strong passwords, fills them in automatically, and syncs them across all your Apple devices. The downside is that it does not work as well on non-Apple devices (Windows computers, Android phones), so if your household has a mix of devices, Bitwarden or 1Password is a better choice. But if you are entirely in the Apple ecosystem, Keychain is free, automatic, and entirely sufficient.
Avoid LastPass. LastPass used to be one of the most popular password managers, but in 2022 it suffered a major data breach in which some encrypted user data was stolen. While the encryption protected most users, the incident eroded trust, and several security experts have stopped recommending LastPass. There are better options now.
The single most important password in your entire digital life is the one you use to log into your password manager. This is the master password, and it deserves more thought than any other password you have ever chosen.
Your master password should be long (at least 14-16 characters), memorable to you, unique (not used anywhere else), and not based on any information someone could find about you (your name, birthdays, addresses, family names, pet names). The most popular technique for creating a strong master password is the 'passphrase' approach: pick four or five random words that have meaning to you but no obvious connection, and string them together. For example: 'CorrectHorseBatteryStaple' or 'TomatoEclipseWarriorMelody.' These are easy to remember but extremely hard for any computer to guess.
Write your master password down — once — on a piece of paper, and store the paper somewhere very safe. Not next to your computer. Not in your wallet. In a fire-safe at home, or in a safe deposit box, or in a sealed envelope given to a trusted family member. The reason to write it down is that if you ever forget it, there is no recovery — the password manager cannot reset it for you, because the master password is what protects all your data. If you lose the master password, you lose access to all your stored passwords. The written copy is your insurance against that.
Never type your master password on any device that does not belong to you. Never share it with anyone except possibly a trusted family member or attorney as part of estate planning. The master password is the key to your entire digital life, and protecting it is as important as protecting the deed to your house.
Setting up a password manager takes about an hour the first time, and the process is largely the same regardless of which one you choose.
Step one: download the password manager software on your computer and install it. Create an account with your email address. Create a strong master password using the passphrase technique above. Write it down and store it safely.
Step two: install the browser extension for the browser you use most often (Chrome, Safari, Firefox, Edge). The browser extension is what lets the password manager fill in passwords automatically when you visit websites. The browser extension is also where most of your day-to-day interactions with the password manager happen.
Step three: install the password manager app on your phone. This lets you use the same passwords on your phone that you use on your computer. The phone app will sync automatically with the computer version through encrypted cloud storage.
Step four: start adding your existing accounts. The easiest way is to import them from your browser. Most browsers (Chrome, Safari, Firefox) have been quietly saving your passwords for years, and most password managers can import them automatically with a few clicks. After the import, you will have a starting list of 20-50 accounts already in your password manager.
Step five: as you log into more accounts in the coming weeks, add the rest manually. Every time you visit a website you have an account on, the password manager will offer to save the username and password. Say yes. Within a few weeks of normal browsing, you will have most of your important accounts in the manager.
Step six (the fun part): start replacing your old reused passwords with strong unique passwords. Each time you log into a website, change the password to something the password manager generates for you. Within a few months, all of your important accounts will have unique strong passwords, and your security will be dramatically better than it was.
Most people who start using a password manager describe the experience as a slight inconvenience for the first week, followed by months of feeling significantly easier than the old way. The initial learning curve is real but short, and the daily benefits compound over time.
What it actually looks like: you visit a website where you have an account. The password manager recognizes the site and pops up a small box offering to fill in your username and password. You click yes, and you are logged in. No typing, no remembering, no checking your notebook. The whole interaction takes about two seconds.
When you create a new account somewhere, the password manager offers to generate a strong unique password for you. You click yes, and the password is created and saved automatically. You never see the password yourself, never type it, never have to remember it. The manager handles everything.
When you visit a site on your phone, the password manager fills in the password there too, synced from your computer. Your accounts work the same way on every device, without you having to remember anything different.
After a few months of this, going back to the old system feels primitive. You will wonder how you ever managed with the same password everywhere, written on a piece of paper. The cognitive overhead of password management — which you probably did not even realize was a burden — disappears, and you can focus on what you actually want to do online instead of struggling with login screens.
The hardest question about password managers is what happens to your accounts when you die. If your spouse, children, or executor cannot get into your password manager, they will not be able to access your email, your bank accounts, your tax documents, your photos, your subscriptions, or any of the other digital infrastructure of your modern life. Many estates have been complicated for years by this problem, and the solution requires a little planning in advance.
Option one: write down your master password and store it in your safe deposit box, along with other important estate documents. Give your executor the key. When they need access, they can open the box and get the password. Make sure the written copy is updated if you ever change the master password.
Option two: use the emergency access feature that most major password managers offer. 1Password and Bitwarden both have systems where you can designate a trusted contact who can request access to your account. If you do not deny the request within a specified period (typically 24-48 hours), they get full access. This protects you while you are alive (because you can deny the request) but gives your trusted contact access after you are gone (because you cannot respond from beyond).
Option three: include a password instruction in your will or with your attorney. The instruction should explain how to access the password manager and what the master password is. Keep it sealed and updated, and make sure your executor knows where to find it.
Whichever option you choose, do not skip this step. The password manager is the gateway to your entire digital life, and if no one can get in after you are gone, your family will face weeks or months of frustration trying to recover access to accounts they need. A few minutes of planning now prevents an enormous amount of pain later.
If you take only one piece of advice from this article, take this: install a password manager this week. Bitwarden is free, takes about an hour to set up, and dramatically improves the security of your entire digital life. There is no better single hour you can spend on technology in 2026, and almost no other improvement you can make has as much downside protection.
The fear of being hacked is real, the consequences of being hacked are severe, and the solution exists and is free. There is no good reason for any adult to still be using the same password everywhere, written on a piece of paper next to the computer. The tool to fix it is sitting in front of you, waiting to be installed. This is the week to do it.