Skip to main content
Privacy Tools

Your Password Manager Is the Only Privacy Tool You Need

Forget VPNs and encrypted email. A password manager is the single highest-impact privacy tool you can adopt today. Here's why, backed by breach data.

859,532. That's how many complaints the FBI's Internet Crime Complaint Center (IC3) logged in 2024, with reported losses of about $16.6 billion — a 33% jump over 2023 (FBI IC3). And the most-reported crime category? Phishing and spoofing, with 193,407 complaints. If you're reading this, you're a target. But you don't need a $10/month VPN or a burner phone to protect yourself. You need to stop reusing passwords. The single best privacy tool you can adopt today is a password manager. Not a VPN. Not encrypted email. A password manager.

Why password managers beat every other privacy tool

Here's the uncomfortable truth: most "privacy tools" are solutions looking for a problem. A VPN hides your IP from your ISP — but your ISP already knows who you are, and the sites you log into know exactly who you are the second you authenticate. Encrypted email protects messages in transit, but most breaches don't start with intercepted email; they start with credentials. Verizon's 2024 Data Breach Investigations Report found that 68% of breaches involve a non-malicious human element, including people falling for phishing (Verizon). And what do attackers get when you fall for phishing? Your password. If that password is reused, they now have access to every account where you used it.

Microsoft notes that password reuse enables password-spray and credential-stuffing attacks, where common or previously breached passwords are tried against corporate accounts (Microsoft Security Blog). In other words, the bad guys aren't hacking in — they're logging in. A password manager stops this cold. It generates unique, random passwords for every account, so a breach at one site doesn't cascade into a breach at ten others. CISA recommends using a password manager to generate and store unique, random passwords for every account, eliminating password reuse (CISA). That's not a feature — that's the whole game.

The breach that proves the point

Have I Been Pwned was created after the Adobe breach — at the time the largest single breach of customer accounts — because the same accounts kept appearing exposed, often with the same passwords (Have I Been Pwned). Let that sink in. The same email-password combos, over and over, across different breaches. That's not a coincidence; that's password reuse at scale. And it's still happening. APWG observed 1,003,924 phishing attacks in the first quarter of 2025 alone — the largest quarterly total since late 2023 (APWG). Every one of those attacks is a chance for someone to hand over a reused password.

Here's a concrete scenario: You signed up for a fitness app in 2019 with the password "Fitness123!". You used the same password for your bank, your email, and your Amazon account. In 2021, the fitness app gets breached. Your credentials appear in a dump. Attackers try that email-password combo on 50 other sites. They get into your email, then reset your bank password, then drain your account. A password manager would have generated a 20-character random string for that fitness app, and the breach would have been a non-event. You wouldn't have to change anything because no other account shared that password.

What about MFA? Yes, but it's not enough alone

"But I have MFA!" Good. You should. Microsoft states that enabling MFA can block over 99.9% of account compromise attacks (Microsoft Security Blog). But MFA has a dirty secret: not all MFA is created equal. CISA documents four ways traditional MFA is bypassed: phishing, push bombing (push fatigue), exploitation of SS7 protocol vulnerabilities, and SIM swapping (CISA). SMS codes are vulnerable to SIM-swapping, where attackers convince your carrier to transfer your number. So if your MFA is a text message, it's better than nothing, but it's not the gold standard. CISA ranks phishing-resistant MFA — FIDO/WebAuthn and PKI-based — as the gold standard, resistant to phishing, push bombing, SS7, and SIM swap attacks (CISA).

Here's the catch: you can't use phishing-resistant MFA everywhere. Many services still don't support it. But a password manager works everywhere, on every account, regardless of what MFA the service offers. It's the universal baseline. And if you use a password manager to generate a unique 16-character password for every site, then even if one site leaks your password, the attacker can't reuse it anywhere else. MFA is a second lock; a password manager ensures the first lock isn't a duplicate key.

The counterargument: "I can't remember 100 random passwords"

You don't have to. That's the point. The NCSC says writing a password down is acceptable if kept somewhere safe, and recommends password managers that can create and store strong, unique passwords (NCSC). You remember one strong master passphrase — something like four random words — and the manager does the rest. CISA recommends passphrases made of 4–7 unrelated words, which may include spaces, as a memorable way to create long, strong passwords (CISA). So your master password could be "correct horse battery staple" — easy for you to remember, hard for anyone else to guess. The manager then generates and fills in the other 99 passwords. You never see them, and you never need to.

The only real downside is the initial setup. You have to go through your accounts and change passwords one by one. It's tedious. But it's a one-time cost. After that, every new account gets a unique password automatically. Compare that to the alternative: checking Have I Been Pwned every few months, discovering your email in yet another breach, and scrambling to change passwords across dozens of sites. That's a recurring nightmare. The password manager is a one-time fix.

What to look for in a password manager

Not all password managers are equal. You want one that:

  • Generates random passwords of at least 16 characters (CISA recommends at least 16 characters — "longer is stronger" — and suggests using a password manager to generate and store them).
  • Supports passphrases of 4–7 unrelated words, in case you prefer something memorable for your master password.
  • Alerts you to breached credentials, or integrates with Have I Been Pwned.
  • Works across all your devices — phone, laptop, tablet — so you're never stuck without a password.
  • Uses zero-knowledge encryption, meaning even the vendor can't see your vault.

You don't need to pay for the fanciest option. Many reputable managers have free tiers that cover the basics. The important thing is that you use one. Today.

Bottom line

Stop treating privacy as a gadget problem. You don't need a VPN, a Faraday bag, or a de-Googled phone. You need to stop reusing passwords. A password manager is the single highest-impact privacy tool you can adopt, and it takes an afternoon to set up. Do it now. Your future self — the one who doesn't get drained by a credential-stuffing attack — will thank you.

Sources

  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • Have I Been Pwned (About) - https://haveibeenpwned.com/About
  • APWG (Phishing Activity Trends Report) - https://apwg.org/trendsreports/

Share this article:

Comments (0)

No comments yet. Be the first to comment!