Password Managers Guide Cheat Sheet

Last Updated: November 21, 2025

Password Manager Comparison

Feature 1Password Bitwarden LastPass Dashlane
Price (Individual) $2.99/mo Free / $10/yr Free / $3/mo $4.99/mo
Price (Family) $4.99/mo (5) $40/yr (6) $4/mo (6) $7.49/mo (10)
Free Plan No Yes (full featured) Yes (1 device) No
Encryption AES-256 AES-256 AES-256 AES-256
Zero-Knowledge Yes Yes Yes Yes
Open Source No Yes No No
2FA Support Yes (TOTP) Yes (TOTP) Yes (TOTP) Yes (TOTP)
Password Sharing Yes Yes (paid) Yes Yes
Breach Monitoring Yes Yes Yes Yes
Emergency Access Yes Yes (paid) Yes Yes
Form Fill Excellent Good Excellent Excellent
Travel Mode Yes No No No
Platforms All major All major All major All major
Browser Extensions All major All major All major All major
Best For Premium features Budget/Privacy Ease of use Business users

Alternative Options

Manager Price Key Features
NordPass Free / $1.49/mo From NordVPN team, XChaCha20 encryption, data breach scanner
Keeper $2.92/mo Military-grade security, encrypted messaging, file storage
Proton Pass Free / $3.99/mo From ProtonMail, open source, integrated with Proton ecosystem
KeePass Free (open source) Fully offline, maximum control, requires technical knowledge
Apple Keychain Free Built into Apple devices, seamless integration, limited to Apple
Google Password Manager Free Built into Chrome/Android, basic features, limited to Google
Firefox Lockwise Free Built into Firefox, syncs across devices, basic features

1Password Setup

Step Instructions
1. Create Account Go to 1password.com → Start Free Trial → Choose plan
2. Master Password Create strong, memorable master password (20+ characters)
3. Secret Key Save your Secret Key - required for new device setup (print and store safely)
4. Emergency Kit Download Emergency Kit PDF with credentials, store in safe place
5. Install Apps Download desktop app and mobile apps from official site
6. Browser Extension Install extension for Chrome/Firefox/Safari/Edge
7. Import Passwords File → Import → Choose source (Chrome, LastPass, CSV, etc.)
8. Create Vaults Organize with vaults: Personal, Work, Shared, Family
9. Enable 2FA Settings → Security → Turn on Two-Factor Authentication
10. Watchtower Check Watchtower for weak/reused/compromised passwords

Bitwarden Setup

Step Instructions
1. Create Account Go to bitwarden.com → Get Started → Choose plan (free is full featured)
2. Master Password Create strong master password - only you know it, cannot be reset
3. Email Verification Verify email address via link sent to your inbox
4. Install Apps Download from bitwarden.com/download - desktop, mobile, CLI
5. Browser Extension Install from browser's extension store
6. Import Data Settings → Import Data → Select format and file
7. Create Folders Organize with folders: Work, Personal, Banking, Social, etc.
8. Enable 2FA Settings → Security → Two-step Login (free: TOTP app, email)
9. Password Generator Configure default password generation settings
10. Vault Health Reports → Vault Health Report → Fix weak/reused passwords
11. Self-Hosting (Optional) Advanced users can self-host on their own server

LastPass Setup

Step Instructions
1. Create Account Go to lastpass.com → Get LastPass Free or Premium
2. Master Password Create strong master password - write down and store safely
3. Browser Extension Install LastPass extension (auto-prompts on first login)
4. Import Passwords More Options → Advanced → Import → Choose browser/manager
5. Mobile Apps Install iOS/Android app (free: one device type, paid: unlimited)
6. Security Dashboard Check Security Dashboard for password health score
7. Enable 2FA Account Settings → Multifactor Options → Enable authenticator app
8. Organize Create folders: Banking, Shopping, Work, Social Media
9. Security Challenge Run Security Challenge to identify weak/duplicate passwords
10. Sharing Set up Sharing Center for family/team password sharing

Dashlane Setup

Step Instructions
1. Create Account Go to dashlane.com → Get Started → Choose plan
2. Master Password Create strong master password (12+ characters, unique)
3. Install App Download desktop and mobile apps
4. Browser Extension Install extension for your browser(s)
5. Import Passwords Settings → Import Passwords → Select source
6. Password Health Review Password Health dashboard for weak passwords
7. Enable 2FA Settings → Security → Two-factor authentication
8. Dark Web Monitoring Enable Dark Web Monitoring for breach alerts
9. VPN (Premium) Premium: Enable built-in VPN for secure browsing
10. Sharing Use Secure Sharing for shared accounts with family/team

Master Password Best Practices

Practice Description
Length Over Complexity Aim for 20+ characters. "correct-horse-battery-staple" beats "P@ssw0rd!"
Use Passphrase String of 4-6 random words easier to remember than complex password
Make It Unique Never reuse your master password anywhere else
Avoid Personal Info No birthdays, names, addresses, or dictionary words
Diceware Method Roll dice to select words from Diceware word list for true randomness
Practice Typing It Type it daily until muscle memory develops
Write It Down (Safely) OK to write down initially, but store in locked safe, not digitally
Never Share Never share master password via email, text, or phone
Change If Compromised If you suspect compromise, change immediately
Example Strong "Sunrise-Elephant-Cathedral-Quantum-2024-Bicycle"

Security Best Practices

Practice Description
Enable 2FA Always enable two-factor authentication on your password manager
Use Unique Passwords Every account should have a unique password generated by manager
20+ Characters Generate passwords with 20+ characters including symbols
Regular Audits Monthly: check for weak, reused, or compromised passwords
Breach Monitoring Enable breach monitoring/dark web scanning features
Update Regularly Keep app and extensions updated for security patches
Secure Devices Use device passwords/biometrics, full disk encryption
Log Out on Shared Always log out on shared/public computers
Review Permissions Regularly review what has access to your vault
Backup Codes Save backup/recovery codes in secure physical location

2FA Integration

Method Security Level Notes
Authenticator App (TOTP) High Best balance of security and convenience. Use Authy, Google Authenticator, Microsoft Authenticator
Hardware Key (U2F/FIDO2) Highest YubiKey, Titan Key - physical device required. Most secure but can lose/break
SMS Low-Medium Better than nothing but vulnerable to SIM swapping. Use as backup only
Email Low-Medium Only if email account is extremely secure with 2FA
Biometric Medium-High Fingerprint/Face ID for device unlock, not account 2FA
Backup Codes N/A Always save backup codes in case you lose 2FA device

Family Sharing Setup

Step Action
1. Upgrade Plan Purchase family plan (typically covers 5-10 people)
2. Invite Members Send email invitations to family members
3. Create Shared Vaults Vaults for: Household Bills, Streaming Services, WiFi, etc.
4. Set Permissions Decide who can view vs. edit shared passwords
5. Personal Vaults Each member maintains private vault for personal accounts
6. Emergency Access Set up trusted contacts who can access vault if needed
7. Waiting Period Configure waiting period for emergency access (e.g., 7-30 days)
8. Family Policy Establish rules: master password requirements, 2FA mandatory, etc.
9. Regular Review Quarterly: review shared items, remove unused accounts

Emergency Access

Feature How It Works
Purpose Allow trusted person to access your vault if you're incapacitated or deceased
Setup (1Password) Not available - use Emergency Kit stored with will/estate documents
Setup (Bitwarden) Settings → Emergency Access → Add trusted emergency contact
Setup (LastPass) Account Settings → Emergency Access → Add trusted contact
Setup (Dashlane) Settings → Emergency → Add emergency contact
Waiting Period You set delay (0-30+ days) before access is granted
Request Process Trusted contact requests access → waiting period starts → you can deny
Access Level View only or full access (can see passwords)
Best Practices Choose spouse, adult child, lawyer, or close family member
Legal Backup Also include password manager info in estate planning documents

Migration Between Managers

Step Instructions
1. Export from Old Settings → Export → Choose CSV or encrypted format
2. Secure Export File CSV is unencrypted - delete file securely after import
3. Import to New New manager → Settings → Import → Select file format
4. Verify Import Check that all passwords transferred correctly
5. Update Extensions Install new browser extensions, remove old ones
6. Test Login Test auto-fill on several important accounts
7. Update Mobile Install new mobile app, configure auto-fill
8. Delete Export Securely delete CSV export file (use file shredder)
9. Cancel Old Service Wait 1 week to ensure everything works, then cancel old subscription

Common Use Cases

Scenario Solution
Shared Netflix Account Create shared vault/folder, add streaming passwords, invite family
WiFi for Guests Create WiFi item with network name & password, easily share via link
Work vs Personal Separate vaults: Personal (your account), Work (company account/vault)
Secure Notes Store: passport info, license numbers, insurance cards, combination codes
Credit Cards Store card details for auto-fill during online shopping
SSH Keys Store private keys, server credentials in secure notes
Travel 1Password: Enable Travel Mode to hide sensitive vaults during border crossing
Elderly Parents Set up password manager, add yourself as emergency contact
Kids Accounts Family vault for kids' account passwords, teach them password security
💡 Pro Tips:
  • Start with the free version of Bitwarden to test if password managers work for you
  • Use browser extension auto-fill rather than copy-paste to prevent clipboard hijacking
  • Enable biometric unlock (fingerprint/face) on mobile for convenience without compromising security
  • Store recovery codes for 2FA in your password manager's secure notes
  • Use password manager's password generator for security questions (treat them as passwords)
  • Set auto-lock timeout to 5-15 minutes on desktop, require authentication on app reopen on mobile
  • Never store master password in password manager - keep it only in your memory
  • For maximum security: hardware key (YubiKey) + authenticator app + backup codes
  • Check "Have I Been Pwned" integration to monitor for data breaches
  • Use different email aliases (yourname+sitename@gmail.com) for better breach tracking
  • Family plan is usually cheaper than 2 individual accounts - share with trusted person
  • Print Emergency Kit/backup codes and store in fireproof safe with important documents
← Back to Data Science & ML | Browse all categories | View all cheat sheets