• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

All Things Secured

Online Security Made Simple

FREE ONLINE SECURITY CHECKLIST! DOWNLOAD NOW

  • Security Basics
    • Start Here (Security Guide)
    • What is a Digital Footprint?
    • What is a VPN?
    • What is 2-Factor Authentication?
    • What is SmartDNS?
    • Bad Security Habits
    • Http vs Https?
  • VPN Security
    • Best VPNs 2024
    • Best Free VPNs 2024
    • VPN Reviews
      • ExpressVPN Review
      • Surfshark Review
      • NordVPN Review
      • ProtonVPN Review
      • VyprVPN Review
      • Mozilla VPN Review
      • IPVanish Review
      • Avast VPN Review
      • Ivacy VPN Review
      • PureVPN Review
    • Frequent Asked Questions
      • Are VPNs Illegal?
      • Tor vs VPN?
      • What is a VPN Kill Switch?
      • What is Split Tunneling?
      • Zero Log VPN?
      • Free VPN vs Paid VPN?
      • Lightway vs WireGuard vs OpenVPN
      • Increase Internet Speed on VPN?
      • How to Watch Netflix in China?
    • 10 Important VPN Features
    • 5 Best VPNs for Routers
    • Common VPN Myths
    • Common VPN Scams
    • VPN Connection Protocols Guide
  • Password Security
    • Password Manager Setup Guide
    • Best Password Managers 2024
      • 1Password Review
      • Dashlane Review
      • NordPass Review
      • Best iOS Password Manager
    • Frequently Asked Questions
      • How Do Password Managers Work?
      • Are Password Managers Safe?
      • Are Chrome Passwords Secure?
    • Double Blind Password Strategy
    • Using Google Authenticator
  • Email Security
    • Secure Email Providers in 2024
    • ProtonMail Review
    • Email Phishing Scams
  • Resources
    • Help! I’ve Been Hacked!
    • Password Strength Checker
    • Security Checklist PDF
    • Digital Death Checklist
  • About
    • Contact
    • Advertise

Are Password Managers Safe in 2025? (+ trick to ensure they are)

February 11, 2025 By Josh

Are password managers safe to use in 2025? Security is a concern whenever you’re dealing with sensitive data, especially when all of that data is going to one place, with one company. Sure, you could go crazy and split your passwords among different password manager apps or just write them all down by hand…but there is a better way. You can have confidence that password managers are safe, and this is how.

Are password managers safe in 2024?

Key Takeaways

  • No single piece of security software is completely foolproof, including password managers, but they’re still better than not using one.
  • Password managers force you to create stronger, unique passwords and use 2-factor authentication, improving your overall security.
  • A few password managers, like LastPass and OneLogin, have been hacked before, exposing user data.
  • With proper precautions like 2FA, a strong master password, and the double-blind method, password managers are generally secure for most people.

As we become more digitally engaged, we all have a ton of passwords to remember.

And since it’s almost impossible to follow all the best practices for passwords, people have started utilizing good password manager apps to secure themselves.

Many password managers act as your digital gatekeepers. They are convenient little apps that help you get rid of weak passwords and then securely store them in an encrypted vault for you to use.

But isn’t that just putting all your eggs in one basket?

If one app stores all your important passwords, what if that app gets hacked? How can you trust the company?

These are valid concerns. So how can we confidently answer the question: Are password managers secure?

Let’s take a look.

Note: Some of the links in this article are affiliate links, which means that at no extra cost to you, I may be compensated if you choose to use one of the services listed.

Fact: No Security Measure is Foolproof

Let me be blunt: if you’re relying on a single piece of software or a single strategy to secure yourself online, you’re setting yourself up to be disappointed and possibly hacked.

No single security software is foolproof…and that includes safe password managers.

No single security software is foolproof.

But as security researcher Troy Hunt has noted, “Password managers don’t have to be perfect, they just have to be better than not having one“.

If you visit a construction site, you’re advised to wear a safety helmet. It won’t protect you from ALL accidents but it is still better than not wearing a safety helmet at all.

There are still hundreds of thousands of people online who secure their accounts with the word “password” as their password. Having a strong password, even if you’re using software that could potentially be exploited, is still better than nothing.

Get a private phone number with Hushed

Password Managers Can and Have Been Hacked

A couple of years back, a security report by independent consulting firm ISE disclosed flaws in the security of a password manager app.

Alarming, right?

All the password manager apps studied by the researchers have the same basic functionality. They are meant to:

  • Create strong passwords using the inbuilt password generator;
  • Store all your passwords (often in the cloud in the case of cloud based password managers);
  • Lock the passwords behind a vault that can only be opened by a master password; and
  • Auto-complete online forms.

The report evaluated the working of Dashlane, 1Password, LastPass, and KeePass on Windows 10. The findings suggest that some passwords were left exposed even when the password manager safe vault was in locked mode.

In some cases, even the master password stayed in the computer’s memory – and that too in plaintext format.

The master password is the key to the password vault, which means if it’s hacked, all passwords are stolen.

Encrypt your internet traffic with ExpressVPN

Unfortunately, these haven’t been isolated incidents. Consider the following:

  • In 2015, LastPass faced an attack that exposed email addresses and security information of users.
  • In 2017, OneLogin was attacked and customer data was leaked. The user data stored in their US data centers was affected.
  • That same year, a vulnerability in the Keeper browser plugin was exposed. This vulnerability allowed hackers to steal any password from the vault. Keeper sued the reporter for publishing the report. While they fixed the bug later before it affected any customer, the move of suing the reporter did not do good to their reputation.
  • In 2022, LastPass was hacked (again) and had a lot of unencrypted meta data on their customers as well as stolen vaults.

I’m not going to sugarcoat it…

…this looks bad.

And it looks bad because when it comes to the question of “Are password managers safe”…it is bad.

But as I’ve mentioned earlier, the fact that password managers aren’t perfect is not a reason to stop using them altogether.

You Should Still Use a Manager App…Here’s Why

Even though time has exposed security flaws in some password managers, using them is often better than not using them. The same goes for most security technologies.

It’s good to ask are password managers safe, but it’s also good to understand their advantages.

Password Managers do several things to improve your secure password etiquette. For example, they:

  • Force you to create new passwords: Instead of reusing all your old passwords, you have to create new ones. All good password manager users get alerts when they’ve used the same password too many times.
  • Force you to create stronger passwords: This means long passwords (12+ characters) that include letters, numbers, symbols, etc. Usually, we don’t do this on our own and you can check your current passwords to see how strong they are.
  • Remind you to use 2-factor authentication: Good password manager apps can tell you which online logins offer 2-factor authentication (2FA) and give gentle reminders to make use of the 2FA feature.

These reasons alone are often worth the price of a secure password manager (even though you can do them all for free). Plus, such software also allows you to take advantage of these advanced password manager tips

However, there is one method I use that allows me to use a password manager app with complete confidence. It’s one of my favorite security hacks that I’d like to share with you.

Yubikey is your key to a safer internet
Get a virtual address with PostScanMail!

Still Having Trust Issues? Try This Hack

What I’m about to share with you is a hack known as the double-blind password method. You’ll find more details in that link, but I’ll quickly walk through it here.

Trust me – it’s worth sticking around and reading this, especially if you’re still uneasy about putting all of your passwords in a password manager app.

But first, as with any life hack, it only works if you’re already covered in the basics. What I mean is this:

  • You’re already using a password manager: I use and have already published a review of 1Password, which has been my favorite among many browser based password managers. They offer a 14-day free trial, so you can try them risk-free yourself avoiding the uncertainty associated with unreliable free password managers.
  • You already use 2-factor authentication: This is a no-brainer, but it bears repeating. If your password manager offers 2FA, use it. If any important online login (i.e. bank, social media, online accounts, etc.) offers 2FA, use it.
  • You already have a strong master password: Please don’t negate the power of a password manager by securing it with a dumb master password. If you need help, take a cue from my strategies for creating a super-secure password.

Ok, with that out of the way, here’s an explanation of the double-blind password strategy:

I’m going to use my bank as an example. When I set up the password for my online banking, I asked my password manager to create a complex password that was 12 digits long.

I copied that into the password creation box but I didn’t stop there. I added 4 more characters (my “unique key”) that only I know to the end of the password, making it a total of 16 digits long.

Password Manager (12 characters) + Personal Touch (4 characters) = True Password (16 characters)

Hidden password strategy

Hopefully, I haven’t lost you here.

What I’m doing is adding a personal password that only I know to the end of the password my manager app gave me.

In the end, when I log in to my account I ask my password manager to auto-fill the stored password and then I add my 4 characters to the end.

Here’s why this strategy works:

It doesn’t matter if somebody hacks into my password manager app and steals all my passwords. Unless they know these extra four characters that I always type into the end of my stored passwords, the data in my password manager app is worthless!

In the end, I get the benefits of a password manager app as well as the confidence that I’m really secure. It doesn’t matter if you’re using Dashlane or 1Password or any other password manager, it works either way.

This takes a little time to implement, but if you’re truly worried about the security of your password manager, this hack is the way to go.

Be sure to subscribe to the All Things Secured YouTube channel!

Final Thoughts | Are Password Managers Safe?

Overall, I recommend using a password manager such as 1Password, even if you question are password managers safe.

For most people, it’s a huge improvement over their current password strategy and forces them to think harder about how they secure themselves online.

Are password manager providers hack-proof?

No.

Are most password managers safe in 2025?

The answer is invariably YES.

Better yet, if you use 2-factor Authentication on top of the double-blind password strategy I shared with you above, you’ll set yourself up to be more secure than probably 95% of the online population right now.

Trust me – hackers would rather grab the low-hanging fruit than to deal with someone like you.

Further Reading & Resources

  • Best Password Manager for 2025
    Best Password Manager 2025 | See & Compare the Differences
  • Dashlane vs 1Password compared
    Dashlane vs 1Password | Comparing Features & Benefits in 2025
  • How secure is the Chrome Password Manager?
    Is Chrome Password Manager Secure in 2024? (be careful)
  • Password manager setup guide for 2021
    How to Use a Password Manager | Beginner's Guide for 2025

Download the Security Checklist!

A Free Resource from All Things Secured

    Reader Interactions

    Comments

    1. Avatar for JoshRob S. says

      March 5, 2020 at 1:07 pm

      I am someone who agrees with the importance of password managers, especially in companies that service multiple clients. That being said, it’s important to take precautions, as you detailed here. I believe the biggest is having multiple levels of verification; this way, it becomes less likely that security will be compromised.

    2. Avatar for JoshC says

      March 26, 2020 at 6:53 pm

      i HAVE TRIED PASSWORD MANAGERS IN THE PASt. I gave up as someone was and still is hacking into all of my online accounts. Every password is different. Ive tried copy and paste methods yet, still it never fails that my accounts are hacked even with 2-step verification. One gmail account was recently hacked into a week after i changed my Password. I logged into my gmail account and when i entered the account, it showed an old phone nimber and it did not have A titan security key that i had established on the account in november of 2019.
      I have been logging every incident since november 2019 and i have exhausted everythIng to Get this hacker (who i believe is a family member) from accessing my accounts. This has been going on since 2013.

      • Avatar for JoshJosh Summers says

        March 29, 2020 at 1:59 am

        I’m sorry to hear about the problems, C. Sounds like it goes deeper than just your password manager. If they can get past 2FA, they must have access to your key.

      • Avatar for JoshAnonymous says

        April 26, 2020 at 4:12 am

        Chances are that a highly skilled family member has installed keylogger/screen Graber software on your computer, that or you suffer from a split personality disorder and you are the one making these changes to your own accounts.

    3. Avatar for JoshPetros ebor says

      April 4, 2020 at 5:11 pm

      the double-blind password strategy sounds brilliant.
      Some anti-virus software has a password manager included in the paid-for package, eg norton security. how good is this, compared to a stand-alone password manager? is it easier to have it all in one package?

      • Avatar for JoshJosh Summers says

        April 5, 2020 at 1:21 am

        If your anti-virus software comes with a password manager, I say use it! It’s better than nothing and it’s cheaper than getting a separate service. The only reason you might want to pay for a separate service is if you don’t like their software.

    4. Avatar for JoshChris says

      July 24, 2020 at 11:55 am

      Your hack idea is a GREAT idea. Thank you!!

      • Avatar for JoshJosh Summers says

        July 25, 2020 at 8:49 am

        I’m glad it’s been helpful, Chris!

    5. Avatar for Joshkeith says

      October 19, 2020 at 9:00 am

      Josh, your double blind idea is smart, very smart.

      • Avatar for JoshJosh Summers says

        October 20, 2020 at 12:21 am

        Thank you, Keith. I appreciate the kind words!

    6. Avatar for JoshAshley says

      October 23, 2020 at 8:36 am

      Brilliant idea! Thanks for this article. What are your thoughts on Keeper vs 1Password? I just have a few questions about how to use the double blind strategy.

      1) So if I understood correctly, when you have the password manager create the new password, you never enter the additional 4 characters “in the app”, you always do that manually before logging into a site, right?

      2) Do all password managers allow you to modify your password before logging in? I know in Chrome I often get a window that pops up showing me my login and password and asking me if I want to save/update it with Chrome or the password manager on my computer, so just wanted to be sure this was the case.

      3) And since I’ve allowed my computer in the past to remember password, do I need to go in and turn that feature off or will it be okay if I just never say again to remember the passwords in Chrome/Windows, etc.?

      Thank you for your time!

      • Avatar for JoshJosh Summers says

        October 25, 2020 at 8:22 pm

        Hi Ashley! Great questions here. I’ll try to answer them the best I can here:

        1. Yes, you always enter the extra characters manually as part of this strategy.
        2. It’s different for every password manager. Dashlane, for example, auto logs in, so you have to turn that feature off. I like 1Password because I can go into the settings and tell the program which URLs I don’t want them to ask me about save/update. I’m not sure if Chrome has that same feature or if you just have to turn off the whole save/update popup globally.
        3. It’s up to you whether you want to turn the feature off. For me, I only use the double blind password on what I consider to be my most sensitive online accounts. It would be a laborious process to set it up for every single login you have 🙂
        • Avatar for JoshDave H says

          December 26, 2021 at 10:42 am

          Hi,
          How do pM’s reply when some logins require yOu to change your pAssword eveRy 30 days?

          • Avatar for JoshJosh says

            December 30, 2021 at 10:54 pm

            This is where PMs shine. They can help you create new, strong passwords and then easily replace the old password each month.

    7. Avatar for JoshSteve/H says

      October 26, 2020 at 6:58 pm

      What Pm’s will allow double blind pass words. Could you comment on the safety of loadinG your passWords from Safari to a PM?

      • Avatar for JoshJosh Summers says

        October 27, 2020 at 1:53 am

        The double blind password strategy works for all password managers, but the reason I prefer 1Password is that you can set an exemption for URLs so that it will stop asking you “do you want to update this password”?

        As for loading your passwords from Safari to a password manager, there’s vulnerability while you’re making the transition, but that’s true of any switch. I recommend that after you make the switch, you change the passwords of your most sensitive accounts with your new password manager.

    8. Avatar for JoshKathie says

      February 22, 2021 at 5:19 pm

      Do you feel that 1Password is the easiest password manager of all password managers?

      • Avatar for JoshJosh Summers says

        February 22, 2021 at 8:22 pm

        I do, but that’s a pretty subjective answer. You can give them a try for 30 days for free, I believe, if you want to test it out yourself.

    9. Avatar for Joshmadelpay says

      March 18, 2021 at 7:46 pm

      I’m new to password managers and really appreciated your article and your 4-digit strategy for sensitive accounts.

      • Avatar for JoshJosh Summers says

        March 18, 2021 at 11:35 pm

        My pleasure! Thanks for reading and leaving a comment, Madelpay.

    Primary Sidebar

    Download the free online security checklist!
    Check your password with this password checker by All Things Secured

    Best Personal Privacy Tools

    Use DeleteMe to Remove Your data onlineDeleteMe (remove personal data online)
    Use Traveling Mailbox to keep your address privateTraveling Mailbox (private virtual address)
    Hushed private second phone numberHushed (private 2nd phone line)

    Recommended Password Managers

    1Password Logo Mark1Password (Best Overall)
    Dashlane Logo MarkDashlane (Best for Businesses)
    Bitwarden Logo MarkBitwarden (Best Free Option)

    Best Secure Email Providers

    ProtonMail Logo MarkProtonMail (Best Gmail Alternative)
    StartMail Logo MarkStartmail (from StartPage)
    Mailfence Encrypted EmailMailfence

    Recommended VPNs

    ProtonVPN Logo MarkProtonVPN (Best Overall)
    NordVPN Logo MarkNordVPN (best for streaming)
    iVPN Logo MarkiVPN

    Best Identity Theft Protection

    Identity Guard Logo MarkIdentity Guard (Personally Recommended)

    Copyright © 2025 · Affiliate Disclaimer 
· Privacy Policy
 · Advertise
 · Contact