Why I Stopped Relying on My Browser's Built-In Password Saving
For years, whenever a website asked if I wanted to save a password, I just clicked yes without thinking about it. My browser was already open, the prompt took one click to dismiss, and the passwords were there again the next time I needed them. It felt like a password manager without the extra step of installing anything. I didn't stop to ask what that convenience was actually costing me until I had a genuinely uncomfortable moment sat in a coffee shop, realising my laptop was unlocked and logged into my browser, and that anyone glancing at the right menu could have seen every password I'd ever saved to it in plain text.
The Convenience That Kept Me Using It Longer Than I Should Have
I want to be fair to the built-in option, because I understand exactly why it's so widely used. It's already there, it costs nothing extra, and it works the moment you say yes to the first save prompt. For someone who's never used a dedicated password manager, that low barrier to entry genuinely does more good than a stronger tool nobody actually sets up. My problem wasn't that it did nothing, it's that I'd let "better than nothing" become "good enough," and those aren't the same standard once you actually rely on a browser for anything beyond casual browsing.
What Happens If Someone Gets Into My Device Itself
The moment that changed my thinking wasn't a hack, it was just sitting in that coffee shop and realising how little stood between my saved passwords and anyone with physical access to my unlocked laptop. Most browsers will show saved passwords in plain text once you're inside the settings menu, sometimes without even asking to re-confirm who you are first. A dedicated password manager locks behind its own separate master password or biometric check, so unlocking my laptop doesn't automatically unlock my vault too. That extra layer sounds small until you picture the exact scenario where it's the only thing standing between someone and my accounts.
Why It Doesn't Follow Me Between Browsers or Devices the Same Way
I also hadn't noticed how much friction the built-in approach was quietly building into my own routine. Passwords saved in one browser mostly stay there, so switching between my laptop's browser and my phone's browser meant either retyping things from memory or digging out my phone to read a saved password off a tiny screen. A dedicated manager sits above all of that as its own app, with a browser extension on every device pointed at the same vault, so the same login works the same way whichever screen I'm sat in front of. I didn't realise how much low-grade friction I'd been tolerating until it disappeared.
The Security Features a Dedicated Manager Has That My Browser Doesn't
Beyond just storing passwords, a dedicated manager actively works for me in ways my browser never did. Mine checks the domain of the page I'm on before offering to fill anything in, so a convincing fake login page simply doesn't get autofilled, which is one of the more reliable ways to catch a phishing attempt before I fall for it. It also flags weak or reused passwords across my whole vault at once, tells me if any of my saved logins have shown up in a known data breach, and generates a proper random password whenever I need a new one instead of me typing another variation on something I'll half-remember. My browser's built-in saving never did any of that, it just stored what I typed.
What Finally Made Me Switch
I'd known all of this in the abstract for a while before I actually did anything about it, which is probably familiar if you're reading this and still using your browser's built-in saving right now. What tipped me over was totting up how many accounts I'd built up over the years, more than I could count without checking, and realising I genuinely didn't know how many of them still shared a password with something else. A dedicated password manager, I switched to using NordPass, turned that unknown into a list I could actually work through, and generating a fresh unique password for each one took an evening rather than the weeks I'd been putting it off for. If you're weighing up which one to get, I've written separately about how I'd choose a password manager if I were starting today.
What I Did With the Passwords Already Saved There
Moving away from browser-saved passwords isn't as simple as just starting to use something new, because the old ones don't disappear on their own. Most browsers let you export what's saved as a file, which I imported into my new manager rather than typing everything out again by hand, and I've written separately about the migration process itself if you want the practical steps. The part people skip is clearing the browser's own saved copies afterwards, since leaving both in place just means you've got two separate places someone could find your passwords instead of one. Once I'd confirmed everything had moved across safely, deleting the browser's own list was one of the more satisfying five minutes I've spent on this.
If you want a second opinion on password security generally, NCSC has straightforward guidance that doesn't assume you're already a technical person, and my free Safety Toolkit walks through this switch alongside the rest of what I actually rely on day to day.
