Journal · Guide · 6 min
Move off browser-saved passwords in an hour
By Ziyarex ·
Letting the browser remember passwords is not a moral failing. It is the default, it works, and it beats writing them on paper. It has two real problems, and neither is the one people worry about.
The first is that the passwords live inside one browser. Change browsers, or try to log in on a phone that syncs with something else, and you are locked out of your own list. So you start reusing something memorable for anything you might need to type by hand.
The second is that reuse is invisible. The browser will happily store the same password for forty sites and never mention it. That is the actual risk: not that someone breaks into your browser, but that one unrelated site gets breached and hands over a password that also opens your email.
First, find out what's already out
Before moving anything, check what has already leaked. Have I Been Pwned takes an email address and tells you which known breaches contained it.
Read the result carefully. It lists the breach and what was exposed. "Email addresses, passwords" on a site you forgot you joined in 2014 matters only if that password is one you still use elsewhere. That is the list you are about to fix.
One honest caveat: a clean result proves very little. It only knows about breaches that became public.
Pick the manager, then leave it alone
Almost any dedicated password manager beats the browser. We list Bitwarden because it is open source, audited, and its free tier is genuinely usable rather than a trial — unlimited passwords on unlimited devices, which is the part competitors charge for.
Install it in two places on day one: the browser extension and your phone. A manager you can only reach at your desk gets abandoned by Wednesday.
The migration, in the order that matters
Do not start by importing everything. Import first and you will have a tidy vault full of the same three passwords.
1. Export from the browser. Every major browser has a password export in settings; it produces a CSV. Import that CSV into your new vault.
2. Delete the CSV properly. It is a plain-text file with every password you own. Empty the trash too. This is the single riskiest object in the whole process, and it exists for about ninety seconds.
3. Run the vault's health check. Every manager has one. It flags reused, weak and breached entries. This is your work queue, and it is usually shorter than you fear — most people have four or five real passwords wearing different hats.
4. Fix in blast-radius order, not alphabetically:
- Email first. Whoever controls your email can reset everything else. This is not a tie for first place.
- Then anything with money: bank, card, payment services, anywhere your card is stored.
- Then identity: phone carrier, cloud account, domain registrar, government logins.
- Then everything reused.
- Then the rest, lazily. Change those as you next log in. Trying to fix two hundred sites in one sitting is how people quit halfway.
5. Turn off the browser's password manager. Not just cleared, off. Otherwise it keeps offering to save things and you end up with two half-lists.
6. Add two-factor to the accounts from step 4. An authenticator app, not SMS where you have the choice. SIM swapping is a real attack and text messages are the weakest of the common options.
The risk you just took on
Be clear-eyed: you have concentrated everything into one vault behind one password. That is a genuinely better trade than reuse across forty sites, but it is a trade.
So the master password has to be strong and memorable without being written into another app. Four or five unrelated words beats a short scramble of symbols — long and typeable wins over clever.
And print the recovery material. Most managers cannot reset your master password, by design, because they never had it. That is the property you are paying for, and it means losing it loses the vault. A printed recovery code in a drawer is not paranoid.
What this doesn't fix
Passkeys are quietly replacing this whole dance on sites that support them, and where a site offers one, take it. But adoption is patchy, and until it is not, you still need the boring vault underneath.