The Password Manager Migration I Actually Went Through
The Password Manager Migration I Actually Went Through
I'd known for years that keeping passwords scattered across memory and browser autofill wasn't a real strategy, but knowing that and actually doing something about it turned out to be two very different problems. Choosing a password manager took me an afternoon of comparing options. Actually moving well over a decade of scattered logins into it took considerably longer, and most of what I'd read beforehand focused entirely on which tool to pick rather than what the move itself actually involves. This is the process I went through, not the shortlist I used to choose the software.
Why I Finally Stopped Putting Off the Move
The thing that finally pushed me to do it wasn't a data breach notification, it was a moment of trying to log into an old account and realising I genuinely couldn't remember which of four password variations I'd used for it. I'd been telling myself the migration would take a whole weekend I never had, which is exactly the kind of excuse that keeps people using the same three passwords for a decade. It took me about ninety minutes spread across two evenings, not a weekend, and most of that time went into the next step rather than the actual software setup.
Exporting What My Browser Already Had Saved
My starting point wasn't a blank slate, it was whatever my browser had quietly saved over the years through its own built-in autofill, which turned out to be well over a hundred entries I'd half forgotten existed. Every major browser has an export option buried in its password settings that produces a plain CSV file, and that file became my actual starting inventory rather than trying to remember and re-enter every login by hand. The catch is that a file like that sits unencrypted on your device for as long as it exists, so I imported it straight into the password manager and then deleted the file immediately rather than letting it linger in my downloads folder.

Working Through the List Instead of Importing It Blind
I could have just imported that whole file and called the job done, but importing blind just moves the same mess into a nicer-looking box. Most password managers will flag reused and weak passwords automatically once you import, and mine turned up more repeated passwords than I wanted to admit to, along with a handful of accounts I didn't even recognise the names of anymore. I went through that flagged list first rather than the full alphabetical one, since that's where the actual risk was concentrated, and it took the job from "everything imported" to "everything imported and actually looked at," which is a meaningfully different thing.
Changing the Passwords That Actually Mattered First
I didn't try to fix every single flagged password in one sitting, because that's how a ninety-minute job turns into something I'd abandon halfway through. Instead I prioritised by consequence: email first, since it's the recovery route into almost everything else, then banking, then anything with stored payment details, and left the low-stakes accounts like old forum logins for whenever I got round to them. That ordering meant the accounts that could actually do damage if compromised were secured within the first sitting, even though the full list took another few evenings to work all the way through.
Setting Up the Unlock Method I'd Actually Use Every Day
A password manager only works if unlocking it is easier than the bad habit it's replacing, so I spent real time deciding how I'd get into it day to day rather than accepting whatever the default was. I use a long passphrase for the master password itself, the same four-random-word method I've written about separately, since that's the one thing that has to live in my head and nowhere else. On top of that I turned on biometric unlock on my phone and laptop, which means I'm not typing the master password out in public more often than I actually need to.
Clearing My Browser's Own Saved Passwords Once the Manager Was Ready
The step I nearly skipped was going back into the browser afterwards and actually clearing out its own saved password store, rather than leaving both systems running in parallel. Having the same credentials sitting in two places doubles the number of places a breach could expose them from, and browser-saved passwords are typically protected by nothing more than whether someone's already logged into your device, which is a much weaker bar than a proper password manager's encryption. I waited a full week after the migration before clearing the browser's store, just to be sure nothing had been missed, and then went through and deleted it properly rather than just clicking "stop saving."
Why I Think of the Manager as Ongoing, Not a One-Time Job
The migration itself was a single afternoon-and-a-few-evenings project, but treating it as finished the moment the import was done would undo most of the point of doing it. I run the same account check-in every few months now, the one I've written about separately, which catches new reused passwords and old accounts I've since abandoned before they turn into the same mess I started with. A password manager makes the daily habit painless, but it's still a tool that needs occasional attention rather than something you set up once and never look at again, and the NCSC has its own guidance on password management worth checking your own setup against. My free Safety Toolkit covers the basics that make everything after the migration easier to keep up.
