Password managers: free vs paid, what actually matters

A Monday-morning scenario, security model, sync, recovery, free options (browser, Bitwarden, Apple, Google) and paid ones (1Password, Dashlane, Proton Pass, KeePass): an honest comparison to choose — and migrate in about an hour.

Scenario: Monday 8:12 a.m., bad news

You open an email: “suspicious activity on your account.” Not movie panic — an average shop, a 2019 signup, the same password as your secondary mailbox and an old forum. You change one secret. Three days later, another site notifies you. Same email / password pair. The problem is not that “you are careless.” It is that your memory was used as a database, and human databases do not survive industrial breach lists.

A password manager does not make you invincible. It makes uniqueness (a different secret per site) almost automatic. Below: free vs paid without a sale catalog, useful criteria, honest limits, a realistic migration.

For the “why it keeps happening” loop, see the twin piece: Why password breaches never seem to stop.

What a password manager actually does

Three jobs, mostly:

  1. Generate long, random secrets (often 16–20+ characters).
  2. Store them in an encrypted vault behind a master password (and ideally a second step).
  3. Fill login forms so you stop recycling.

Often also: notes, breach alerts (frequently via Have I Been Pwned), family sharing, temporary codes (TOTP — one-time codes for two-step authentication), and increasingly passkeys (passwordless sign-in keys).

What it does not do: save you if you type the master on a fake site; replace antivirus or a VPN; stop a badly built site from getting hacked (but it limits spread); spare you from thinking about recovery.

The EFF (Surveillance Self-Defense) and the spirit of NIST digital identity guidance converge: length + uniqueness + a tool beat mnemonic gymnastics and “must include uppercase + symbol” rules that push predictable variants.

Criteria that actually matter

Security model

Client-side encryption (the vendor should not read your vault in plaintext), robust master-password derivation, multi-factor authentication (MFA) on the manager account, clear docs (Bitwarden security pages, 1Password white papers). “Zero-knowledge” (the vendor does not know your secrets): check the architecture, not only the slogan.

Sync

Cloud = convenience. Local-only (KeePass family) = control + backup burden. Neither is “safer” by magic: it is a trade among convenience, attack surface, and discipline.

Experience

If autofill fails half the time, you will return to Summer2024!. The tool you use beats the perfect tool you abandon.

Recovery

Forgot the master? Printed kit, trusted contacts — or no safety net by design. Read that page before you put the bank in.

Audits and price

Audits, bug bounties, open source (Bitwarden, KeePassXC…) reduce opacity without guaranteeing zero flaws. Free is not automatically a trap (Apple/Google monetize elsewhere). Paid mostly buys polished sync, family features, support — not an absolute fortress.

Vault security

Free often fine Modern encryption on Bitwarden free, Apple, Google, major browsers.

Paid mainly adds Granular sharing, reports, support — not a new crypto miracle every month.

Multi-device sync

Free often fine Yes inside an ecosystem (Apple / Google) or via Bitwarden free.

Paid mainly adds Smooth sync outside silos, families, more integrations.

Autofill & UX

Free often fine Enough inside one ecosystem.

Paid mainly adds Better cross-platform experience (Windows + iPhone, Android + Mac).

Breach alerts

Free often partial Google, Apple, Bitwarden depending on tier.

Paid mainly adds Broader monitoring — useful if you act, useless if you ignore emails.

Sharing & family

Free often limited Rudimentary or missing sharing.

Paid mainly adds Shared vaults, roles, family recovery — the real “stop pasting Wi‑Fi into chat” case.

Recovery

Free varies Apple/Google tied to the account; Bitwarden expects you to manage the master well.

Paid mainly adds Emergency kits, trusted contacts — configure on day zero.

Comparison tables (indicative)

Public list prices (August 2026), usually cheaper with annual billing. Promos and currencies move — always check the official page before you pay. “≈” means ballpark USD as shown on many vendor sites.

Platforms and pricing

Tool Windows Mac Linux Mobile Free Individual (annual) Individual (monthly)
Bitwarden Yes Yes Yes iOS / Android Yes (solid) ≈ $1.65/mo (Premium ≈ $20/yr) Often close to annual; verify
1Password Yes Yes Yes iOS / Android 14-day trial ≈ $3.99/mo (≈ $48/yr) Higher than annual
Proton Pass Yes Yes Yes iOS / Android Yes (freemium) Pass Plus ≈ $2–3/mo annually ≈ $5/mo (ballpark)
Dashlane Yes Yes Limited / no native iOS / Android Very limited / trial Premium ≈ $3–5/mo annually Higher outside promos
KeePassXC Yes Yes Yes Via third-party apps Yes (100%)
Apple Passwords Limited (iCloud) Yes No iOS / iPadOS Yes (Apple ecosystem)
Google Password Manager Via browser Via browser Via browser Android / iOS Yes (Google account)

Family ballparks (annual): Bitwarden Families ≈ $4/mo for up to 6; 1Password Families ≈ $6/mo for up to 5; Proton Pass Family ≈ $5/mo for up to 6. Confirm on the vendor site.

Useful features

Tool Cloud sync TOTP (2FA codes) Passkeys Sharing / family Open source Self-host
Bitwarden Yes Yes (Premium for built-in, depending on offer) Yes Yes (Families / org) Yes Yes (possible)
1Password Yes Yes Yes Yes (very polished) No No (vendor cloud)
Proton Pass Yes Plan-dependent Yes Yes (paid plans) Partial / ecosystem No (Proton SaaS)
Dashlane Yes Yes Yes Yes No No
KeePassXC You (file / personal sync) Via plugins / apps Improving / variable Shared file (manual) Yes Yes (by design)
Apple iCloud Yes (codes) Yes Limited Apple sharing No No
Google Google account Via Google accounts Yes (device-dependent) Limited No No

Quick read: multi-OS (Windows + Mac + Linux) → Bitwarden, 1Password, Proton Pass, KeePassXC. Apple-only household → Apple is often enough. Zero budget + seriousness → Bitwarden free or KeePassXC if you own sync. Non-technical family → 1Password or Bitwarden Families often buy the comfort.

Free options: useful, clear limits

Browsers (Chrome, Edge, Firefox, Safari): zero friction, already there. Glued to a browser / account; family sharing often weak. For Chrome + Android only, still a huge upgrade over a notebook or Password1.

Google Password Manager (passwords.google.com): Google-account sync, strong suggestions, breach alerts. Limits: dependence on that account, less polished outside Chrome, more power in one giant. Honest for many — not ideal if you want distance from Google.

Apple Passwords / iCloud Keychain: excellent inside the Apple garden (sync, biometrics, passkeys). Add a Windows PC or Android phone and it cracks. All-Apple household → often the smoothest free choice.

Bitwarden free: generous open-source reference — unlimited items, sync, extensions, apps. Free pushes toward Premium for some advanced features (attachments, integrated TOTP depending on offer, families). For an individual with no budget, often the best seriousness-to-price ratio. Read their security docs, not only YouTube.

Beware obscure 4.9-star apps: a bad manager centralizes all your secrets. The downside is asymmetric.

Paid options: strengths and weaknesses

1Password — polished UX, Secret Key + master model, family/team sharing, solid security docs. Among the pricier options; you pay for comfort and adoption, not absolute guarantees. Strong when the family must actually stick with it.

Bitwarden Premium / Families — same open-source base, unlocked features, family/org plans, often lower price, self-hosting possible. UX good but less “premium design”; self-hosting only helps if you own backups and updates.

Dashlane — mainstream onboarding, alerts, sometimes a bundled VPN. The “all-in-one” perimeter can blur what you pay for; compare to real need (often: vault + sync + sharing).

KeePass / KeePassXC — encrypted file under your control, mature open source. No mandatory SaaS — but you own sync, backups, mobile clients. Excellent for technical profiles; high friction for a non-technical family. Not “safer” if the only file dies with the drive.

Proton Pass — privacy coherence in the Proton ecosystem, freemium then paid. Younger on some workflows: test autofill on your critical sites before migrating 200 entries.

None replaces MFA on your primary email.

When free is enough vs when paid makes sense

Free is often enough if you live in one ecosystem, you are alone on your accounts, you actually generate unique secrets, and the parent account (Apple ID / Google) has MFA.

Paying makes sense if you juggle Windows + iPhone (or Android + Mac), you need couple/flatshare sharing without pasting into chat, you want clear family recovery, or you prefer a vendor whose product is the vault.

Paying without changing habits (weak master, MFA off) wastes money. Well-used Bitwarden free beats poorly configured 1Password.

To place these tools in broader hygiene, see also /en/tools — without an affiliate storefront.

Migration in 30–60 minutes

  1. Pick (built-in for zero friction; Bitwarden for dedicated free; paid for family / multi-OS).
  2. Create a long master (5+ uncommon-word phrase). Enable MFA on the manager.
  3. Print / store offline the recovery kit the same day.
  4. Import the browser (official export) — then delete plaintext CSVs.
  5. Prioritize: primary email → bank / taxes → Apple/Google/Microsoft → shops with a saved card.
  6. For each priority: new unique secret, save, sign out dubious sessions.
  7. Everything else as you go. Day-one perfection is how people quit.

Check your email on Have I Been Pwned to prioritize — not to collect anxiety.

Passkeys: complement, not a total replacement

Passkeys (FIDO) tie a crypto key to your device / biometrics / manager. Against phishing, a fake site has a much harder time getting you to “hand over” a passkey like a password. Managers are also becoming passkey wallets.

Not universal yet. 2026 strategy: enable passkeys where offered (email, banks, major platforms); keep a manager for the rest; do not cut MFA “because passkey” without understanding account recovery.

Common mistakes

Short or reused master; no MFA on the vault; CSV export on the Desktop for months; sharing the master as a couple instead of a shared vault; ignoring recovery until the phone is in a puddle; migrating everything… except email; believing the manager replaces MFA; rotating every 30 days with no incident (fatigue, weak variants — change on doubt or breach, in the spirit of NIST / ANSSI).

10-minute action plan

  1. Enable saving / generation in your phone or browser (or create Bitwarden).
  2. Change the password on your primary email to a unique generated secret.
  3. Turn on two-step authentication on that email (authenticator app rather than SMS when you can).
  4. Tomorrow: import the browser, handle bank + app stores.
  5. For breach mechanics and the checklist: Why password breaches never seem to stop.

The goal is not a perfect fortress. It is to stop offering the same key to every lock.

Going further

Sources

Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us

Keep exploring

France Identité: useful tool or trap?

Official app tied to France’s credit-card-format ID, NFC, one-time ID proofs, FranceConnect / FranceConnect+, town-hall certification: what it really changes — and the risks (phone theft, dependency, exclusion).

Read the article