← all articles

Where to keep passwords compared: password manager alternatives

Every “best password manager” list assumes you’ve already decided that a dedicated password manager is the answer. A lot of people haven’t, and for good reason. Maybe you don’t trust a single company holding every credential you own. Maybe you’ve had a sync conflict eat a vault before. Maybe you just want to know what you’re actually giving up if you use something simpler.

This isn’t a ranking. It’s a comparison of where passwords can live, what each option is actually defending against, and where it falls apart. None of these fixes everything, and anyone telling you one tool solves your security is skipping the threat model part.

What you’re actually defending against

Before comparing storage methods, it helps to separate the things that can go wrong:

  • Phishing: you’re tricked into typing a real password into a fake site.
  • Credential stuffing: a password you reused gets leaked from one breach and tried everywhere else.
  • Device theft or loss: someone gets physical access to your laptop or phone.
  • Malware on your device: something reads your clipboard, keystrokes, or files.
  • Vendor breach: the company storing your data (a password manager, your browser sync account, a cloud provider) gets compromised.
  • Shoulder surfing or casual snooping: someone nearby sees what you type or leaves lying around.

No storage method handles all six equally well. Comparing them means asking which of these each one actually reduces, not which one sounds most secure in a headline.

Dedicated password managers

A standalone password manager encrypts your vault locally before it ever leaves your device, then syncs the encrypted blob across your devices through the vendor’s servers. This is usually called a zero-knowledge design: the vendor stores ciphertext it can’t read, because the decryption key is derived from your master password, which never leaves your device.

What this protects against: vendor breach (an attacker who steals the encrypted database still needs your master password to do anything with it), and cross-device convenience means you’re less likely to reuse passwords out of laziness, since the manager can generate and store a unique one per site.

What it doesn’t protect against: a compromised endpoint. If malware is already running on your machine with your vault unlocked, it can read whatever the vault exposes, the same as any other app. It also doesn’t protect you from typing your master password into a phishing page that mimics the manager’s own login screen, which is a known attack pattern against this category specifically.

Browser built-in password managers

Chrome, Firefox, Safari and Edge all offer to save and autofill passwords, syncing them through your browser account the same way a dedicated manager syncs through its own servers. The mechanics are similar: encrypted sync, tied to an account password.

The practical difference is exposure surface. A browser is also your email client, your banking portal, and your extension host, all in one process. A malicious or compromised browser extension can, in some cases, access saved credentials or intercept autofill, something that’s architecturally harder in an app that isn’t also rendering arbitrary web content all day. Browser managers have also historically lagged on features like breach monitoring or shared vaults, though that gap has narrowed over the past few years.

If you’re already careful about what extensions you install and keep your browser updated, a browser-based manager is a legitimate, working option, not a compromise you’re stuck making because you couldn’t be bothered to install something else.

Operating system keychains

macOS Keychain and Windows Hello / Credential Manager store credentials at the OS level, often backed by hardware, like the Secure Enclave on Apple devices or a TPM on Windows machines. Unlocking typically ties to your device login: Face ID, Touch ID, a PIN, or Windows Hello biometrics.

The security model here leans on the hardware. The encryption keys can be bound to a physical chip that refuses to release them without the right biometric or PIN check, and that chip is built to resist extraction even if someone has your device in hand. This is a real, meaningful protection against casual device theft.

The tradeoff is portability. Keychain data doesn’t move cleanly to a Windows machine, and Windows Credential Manager doesn’t sync to your phone unless you’re inside Microsoft’s own ecosystem tools. If you’re single-platform, this is a strong default. If you move between an iPhone, a Windows desktop, and a Linux box, you’ll be maintaining passwords in more than one place, which reintroduces the reuse temptation.

Local encrypted vault files

Software like KeePass keeps your vault as a single encrypted file on your own storage, with no vendor server involved at all. You control the encryption key, you control the file, and there’s no company database of everyone’s vaults sitting somewhere to be a target.

This removes vendor breach from the list entirely, because there’s no vendor holding your data. What it adds back is you becoming the entire backup and sync infrastructure. If the file is on one laptop and that laptop dies, the vault is gone unless you backed it up somewhere. People who use this approach often sync the file themselves through their own cloud storage, which is a reasonable workaround, but it means you’ve reinvented sync without the vendor’s testing, redundancy, or conflict resolution behind it.

This suits people who specifically don’t want a company holding metadata about which sites they log into, and who are disciplined about backups. It doesn’t suit people who want it to just work across devices without thinking about it.

Passkeys and hardware security keys

Worth separating out because they’re not password storage at all. A hardware security key using FIDO2/WebAuthn, or a passkey stored on your device, replaces the password for a given site with a cryptographic key pair. The private key never leaves the device or key, and the site only ever sees a signed challenge.

This is a genuinely different threat model, because there’s no password to phish. A fake login page can’t extract a credential that doesn’t exist in transmittable form. The catch is adoption: not every site supports passkeys yet, so for most people this sits alongside a password manager rather than replacing it, at least for now.

Paper and memorization

Writing a password on paper stored somewhere physically secure, like a locked drawer at home, removes it from every digital attack surface: no malware, no browser extension, no cloud breach. What it exposes you to is physical access and simple loss. It doesn’t scale past a handful of accounts, and it’s genuinely bad for anything you need while away from that specific location.

Memorization has the same physical-access resistance and the same scaling problem, plus a well documented human one: people who memorize passwords tend to reuse simpler ones across sites, because generating and recalling forty unique strong passwords isn’t realistic for most brains. A passphrase system, several unrelated words strung together, is more memorable and more resistant to guessing than a short complex string, but it’s still one password doing the work of one account unless you’re memorizing several.

Picking based on your actual setup

There’s no universal answer here, and anyone selling you one is selling, not advising. A journalist worried about targeted phishing has a different priority list than someone who just wants to stop reusing the same password on twelve shopping sites. Someone on a single Apple device has less reason to look past Keychain than someone juggling three operating systems for work.

What matters is naming your actual risk, phishing, device theft, vendor breach, malware, and picking the storage method that addresses it, rather than the one with the most confident marketing copy.

If you want more explainers like this one that stay specific about what a tool does and doesn’t defend against, come back to The Privacy Wire.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →