Plenty of sensible people have made up their minds about password managers. They watched LastPass, one of the biggest names in the business, suffer a breach that ended with attackers holding copies of customer vaults. They keep hearing that passkeys are about to retire the password anyway. And they conclude, reasonably enough, that putting every login you own inside a single app is the kind of clever idea that ends badly, so the careful move is to stay away.
We think that conclusion gets the risk backwards, and we say so from a particular seat. We run a software download library, which means we spend our days around installers, license keys, and the accounts that hold them all together. From here the pattern is hard to miss: the people getting hurt are almost never the ones who trusted a vault. They are the ones who reused a password. In practice, refusing a password manager has become the gamble, and using one has become the boring, sensible bet.
The attack is aimed at your habits, not your vault
Almost nobody gets their password guessed anymore. The attack that actually reaches ordinary people is duller and far more industrial. Criminals take passwords stolen from one site and try them everywhere else, automatically, millions of attempts at a time. The trade calls it credential stuffing, and it works for one reason only: people reuse passwords.
The scale is difficult to overstate. In June 2026, researchers at Cybernews found an unlocked database sitting on the open internet with roughly 24 billion stolen login records inside, readable by anyone who found the address. When the same team analyzed more than 19 billion leaked credentials, 94 percent turned out to be reused or duplicated. Verizon’s Data Breach Investigations Report found stolen credentials to be the most common starting point for confirmed breaches, ahead of phishing. And this is not some distant enterprise problem: in June 2026, Chick-fil-A loyalty accounts were hijacked in exactly this way, with passwords stolen from other sites replayed against a restaurant app until enough of them worked.
It is tempting to answer that your accounts are not worth stealing. That case punctures the idea. Attackers were not after state secrets; they were after fast-food rewards, because at automated scale, small accounts in bulk pay better than big ones taken slowly. Any account with a stored card, a gift balance, or a mailbox behind it is inventory to someone.
A newer wrinkle makes it worse. A growing share of stolen credentials now comes from infostealer malware, which lifts logins straight off infected computers, and those records arrive labeled: each password sits next to the exact site it opens, so the attacker no longer has to guess where you reused it.
A password manager retires this entire category of attack for you. When every account carries its own long, random password, a breach at one site stays a breach at one site, and nothing spreads to the rest of your life. No memory trick, notebook, or personal password formula achieves the same thing, because every one of those collapses back into patterns and reuse somewhere past the first few dozen accounts.
There is a quieter benefit that gets less airtime. A manager fills your login by matching the address of the site asking for it, so on a fake page dressed up as your bank, the autofill stays silent. That silence is a phishing alarm you did not have to be clever, or even awake, to notice.
What the LastPass breach actually proved
The consensus we opened with rests on that breach, so it deserves a straight look rather than a wave of the hand. Part of it is simply right, and we concede it without wriggling. A weak master password really is a single point of failure. A computer already infected with malware defeats a vault along with everything else on the machine. And LastPass earned the distrust it collected, less for being attacked than for how slowly and vaguely it told its customers what was taken.
But look at what the incident demonstrated. The stolen vaults were encrypted, so users who had chosen strong master passwords were holding, in effect, a stolen safe with no key inside it. Reputable managers are built on zero-knowledge design, meaning the company stores your vault but cannot read it, and neither can whoever robs the company. Now compare that honestly with the alternative. Password reuse fails silently, constantly, with no encryption in the way and no news story to warn you it happened. One approach has a rare worst case you can survive. The other has a common one that is already underway.
And if trusting a company still sits wrong with you, that instinct does not point away from password managers. It points toward a different kind: open-source tools whose code anyone can inspect, or offline vaults that never leave your own device. The category is wider than its worst headline.
The passkey era still needs the vault
The newer half of the consensus says passwords are dying anyway, so why adopt a tool for managing them? Passkeys, which replace the typed password with cryptography tied to your device, really are better. They resist phishing in a way passwords never will, and wherever a site offers them, you should turn them on.
Then look at any real person’s accounts. A handful of big platforms support passkeys. Dozens of smaller services, older tools, and government portals do not, and some will take years to get there. The transition is long and messy, and the place where that messy middle gets managed is, in practice, a password manager: modern ones store and sync passkeys alongside the passwords you are still stuck with, which is why the UK’s National Cyber Security Centre keeps recommending them. Far from being retired by the passkey era, the vault is how you cross into it.
So here is what we would actually do, in order. Pick one manager and commit to it, cloud-synced or offline, paid or free. Let it generate a unique password for every account, starting with your email, because whoever controls your inbox can reset almost everything else you own. Protect the vault itself with a long passphrase and two-factor authentication. While you are at it, run your email address through a breach-check service such as Have I Been Pwned; knowing which of your old passwords are already circulating tells you which accounts to fix first. Then enable passkeys wherever they exist. The whole job fits in a weekend, most of it in one evening.
Our prediction is unglamorous. Passwords will still be with us in five years, the credential dumps will keep setting records, and the gap will keep widening between people whose accounts share a single failure and people whose accounts share none. You do not need to outsmart anyone; you need to stop being the easy case, and this one tool does that on its own. The rest of our security and privacy coverage picks up from there.
