1Password, revisited: one password is still all you need to remember
Reusing one password is still how breaches do their damage. A password manager fixes that, and my 2012 advice on setting one up is rewritten for 2026.
Back in 2012, LinkedIn was hacked and six million passwords turned up on the internet. I wrote a post that week recommending 1Password, and the argument in it has held up better than almost anything else I wrote at the time, but the mechanics around it have not. It told you to sync your vault over Dropbox, to generate passwords at a website that no longer exists, and to set the length field to 14. So rather than let the old version keep giving out advice I’d no longer give, I’m replacing it.
The problem hasn’t moved
The reason LinkedIn mattered wasn’t LinkedIn. It was that most people used the same password there as everywhere else, so one leaked list opened their email, their PayPal and whatever else they’d signed up to with it. That’s still how breaches do their damage. Attackers don’t crack your password; they take a list from one site and try it on a hundred others, and the only thing that stops them is your password on site B being different from your password on site A.
Nobody can hold a hundred different passwords in their head, which is why they reuse them, which is why the fix was never “try harder to remember”. The fix is to stop remembering altogether. A password manager keeps every login in an encrypted vault, invents a long random password for each new account, and fills it in when you get there. You remember one password — the one that opens the vault — and the software remembers the rest.
What’s changed since 2012
The argument is the same; the product has moved on a long way, and most of what I told you to do back then is now either automatic or wrong.
- Sync is built in. There’s nothing to set up any more: your vault is on your phone, your laptop and your browser, and a login you save on one is on the others before you’ve put the phone down.
- Generation is built in, and longer. The manager makes the password when you create the account. Let it, and let it make something twenty characters or more. The 14 I recommended in 2012 was reasonable for 2012 hardware and isn’t now.
- Two-factor codes live in the vault too. The six-digit codes you’d otherwise fish out of an authenticator app can sit alongside the login they belong to, and get filled in the same way.
- Passkeys are stored there as well. Where a site lets you skip the password entirely and sign in with Face ID or a fingerprint, the manager holds the passkey, so the vault is slowly becoming the place your identity lives, not just your passwords.
- It tells you when you’ve been breached. 1Password’s Watchtower checks your saved logins against known leaks and flags the ones to change. In 2012 you found out from the news.
I still use 1Password, and it’s still what I’d recommend to anyone who asks. Bitwarden is good and free, and Apple’s Passwords app is fine if you live entirely inside Apple devices. Which one matters far less than using one.
What to do
If you’re not using a manager yet, the whole job is an afternoon.
Install it on every device you own, including the browser extension, because the extension is what makes it effortless. Then simply start saving logins as you use them — there’s no need to sit down and enter a hundred accounts in one go. As each one comes up, if the password it’s holding is your “usual” one, change it there and then and let the manager generate the replacement. Turn on two-factor authentication for anything that matters (email, banking, the manager itself) and store the codes in the vault. Over a few weeks every account you actually use will have been swept up, and the ones you don’t use will be the ones you’d forgotten you had.
The one password you do still have to remember is the master password, and it’s worth getting right, because it protects everything else. Make it a long passphrase rather than a short clever string; I’ve written about how to create a strong, memorable password for exactly this case. And where a service offers passkeys, take them; every account that stops using a password is one less thing that can leak.
When every site you visit has a unique, random password that you’ve never seen and never typed, you stop caring which company got hacked this week. You now only have one password to remember — just like you wanted.
This post replaces my original June 2012 guide, written in the week of the LinkedIn breach. The advice to use a password manager is unchanged; the mechanics — Dropbox sync, a third-party generator, 14-character passwords — are not, and have been removed.
