"Isn't putting all my passwords in one place risky?" is the most common hesitation. Here's the honest answer, including the limits.
Two questions come up almost every time password managers get recommended: isn't it risky to put every password in one place, and what happens if the password manager itself gets hacked? Both are fair questions, and both deserve real answers rather than just reassurance.
A well-built password manager doesn't store your passwords in a way anyone — including the company running it — can simply read. Your vault is encrypted using a key derived from your master password, which never gets sent to the company's servers. If an attacker breached the company and stole the encrypted vault database, what they'd have is unreadable without your specific master password. This is the same zero-knowledge principle covered in our companion article on what that term actually means.
In practice, this means a breach of the company's servers and a breach of your specific account are two very different events. Company-side breaches of encrypted vault data have happened in this industry — and in the well-documented cases, the actual damage came down to how strong each individual user's master password was, not a mass exposure of readable passwords.
The security of the entire system rests on one thing: your master password. Everything else — the encryption, the zero-knowledge architecture, the company's own security practices — is protecting a vault that's only as strong as the single key unlocking it. A weak or reused master password undermines all of it.
Being honest about limits matters as much as explaining the protections. A password manager can't help if:
None of these are reasons to avoid a password manager — reusing weak passwords across dozens of sites is a far larger real-world risk than any of the above. But going in with realistic expectations, rather than treating it as an invincible solution, is what actually keeps people safe long-term.