Password managers: free vs paid, what actually matters
A Monday-morning scenario, security model, sync, recovery, free options (browser, Bitwarden, Apple, Google) and paid ones (1Password, Dashlane, Proton Pass, KeePass): an honest comparison to choose — and migrate in about an hour.
Scenario: Monday 8:12 a.m., bad news
You open an email: “suspicious activity on your account.” Not movie panic — an average shop, a 2019 signup, the same password as your secondary mailbox and an old forum. You change one secret. Three days later, another site notifies you. Same email / password pair. The problem is not that “you are careless.” It is that your memory was used as a database, and human databases do not survive industrial breach lists.
A password manager does not make you invincible. It makes uniqueness (a different secret per site) almost automatic. Below: free vs paid without a sale catalog, useful criteria, honest limits, a realistic migration.
For the “why it keeps happening” loop, see the twin piece: Why password breaches never seem to stop.
What a password manager actually does
Three jobs, mostly:
- Generate long, random secrets (often 16–20+ characters).
- Store them in an encrypted vault behind a master password (and ideally a second step).
- Fill login forms so you stop recycling.
Often also: notes, breach alerts (frequently via Have I Been Pwned), family sharing, temporary codes (TOTP — one-time codes for two-step authentication), and increasingly passkeys (passwordless sign-in keys).
What it does not do: save you if you type the master on a fake site; replace antivirus or a VPN; stop a badly built site from getting hacked (but it limits spread); spare you from thinking about recovery.
The EFF (Surveillance Self-Defense) and the spirit of NIST digital identity guidance converge: length + uniqueness + a tool beat mnemonic gymnastics and “must include uppercase + symbol” rules that push predictable variants.
Criteria that actually matter
Security model
Client-side encryption (the vendor should not read your vault in plaintext), robust master-password derivation, multi-factor authentication (MFA) on the manager account, clear docs (Bitwarden security pages, 1Password white papers). “Zero-knowledge” (the vendor does not know your secrets): check the architecture, not only the slogan.
Sync
Cloud = convenience. Local-only (KeePass family) = control + backup burden. Neither is “safer” by magic: it is a trade among convenience, attack surface, and discipline.
Experience
If autofill fails half the time, you will return to Summer2024!. The tool you use beats the perfect tool you abandon.
Recovery
Forgot the master? Printed kit, trusted contacts — or no safety net by design. Read that page before you put the bank in.
Audits and price
Audits, bug bounties, open source (Bitwarden, KeePassXC…) reduce opacity without guaranteeing zero flaws. Free is not automatically a trap (Apple/Google monetize elsewhere). Paid mostly buys polished sync, family features, support — not an absolute fortress.
Vault security
Free often fine Modern encryption on Bitwarden free, Apple, Google, major browsers.
Paid mainly adds Granular sharing, reports, support — not a new crypto miracle every month.
Multi-device sync
Free often fine Yes inside an ecosystem (Apple / Google) or via Bitwarden free.
Paid mainly adds Smooth sync outside silos, families, more integrations.
Autofill & UX
Free often fine Enough inside one ecosystem.
Paid mainly adds Better cross-platform experience (Windows + iPhone, Android + Mac).
Breach alerts
Free often partial Google, Apple, Bitwarden depending on tier.
Paid mainly adds Broader monitoring — useful if you act, useless if you ignore emails.
Sharing & family
Free often limited Rudimentary or missing sharing.
Paid mainly adds Shared vaults, roles, family recovery — the real “stop pasting Wi‑Fi into chat” case.
Recovery
Free varies Apple/Google tied to the account; Bitwarden expects you to manage the master well.
Paid mainly adds Emergency kits, trusted contacts — configure on day zero.
Comparison tables (indicative)
Public list prices (August 2026), usually cheaper with annual billing. Promos and currencies move — always check the official page before you pay. “≈” means ballpark USD as shown on many vendor sites.
Platforms and pricing
| Tool | Windows | Mac | Linux | Mobile | Free | Individual (annual) | Individual (monthly) |
|---|---|---|---|---|---|---|---|
| Bitwarden | Yes | Yes | Yes | iOS / Android | Yes (solid) | ≈ $1.65/mo (Premium ≈ $20/yr) | Often close to annual; verify |
| 1Password | Yes | Yes | Yes | iOS / Android | 14-day trial | ≈ $3.99/mo (≈ $48/yr) | Higher than annual |
| Proton Pass | Yes | Yes | Yes | iOS / Android | Yes (freemium) | Pass Plus ≈ $2–3/mo annually | ≈ $5/mo (ballpark) |
| Dashlane | Yes | Yes | Limited / no native | iOS / Android | Very limited / trial | Premium ≈ $3–5/mo annually | Higher outside promos |
| KeePassXC | Yes | Yes | Yes | Via third-party apps | Yes (100%) | — | — |
| Apple Passwords | Limited (iCloud) | Yes | No | iOS / iPadOS | Yes (Apple ecosystem) | — | — |
| Google Password Manager | Via browser | Via browser | Via browser | Android / iOS | Yes (Google account) | — | — |
Family ballparks (annual): Bitwarden Families ≈ $4/mo for up to 6; 1Password Families ≈ $6/mo for up to 5; Proton Pass Family ≈ $5/mo for up to 6. Confirm on the vendor site.
Useful features
| Tool | Cloud sync | TOTP (2FA codes) | Passkeys | Sharing / family | Open source | Self-host |
|---|---|---|---|---|---|---|
| Bitwarden | Yes | Yes (Premium for built-in, depending on offer) | Yes | Yes (Families / org) | Yes | Yes (possible) |
| 1Password | Yes | Yes | Yes | Yes (very polished) | No | No (vendor cloud) |
| Proton Pass | Yes | Plan-dependent | Yes | Yes (paid plans) | Partial / ecosystem | No (Proton SaaS) |
| Dashlane | Yes | Yes | Yes | Yes | No | No |
| KeePassXC | You (file / personal sync) | Via plugins / apps | Improving / variable | Shared file (manual) | Yes | Yes (by design) |
| Apple | iCloud | Yes (codes) | Yes | Limited Apple sharing | No | No |
| Google account | Via Google accounts | Yes (device-dependent) | Limited | No | No |
Quick read: multi-OS (Windows + Mac + Linux) → Bitwarden, 1Password, Proton Pass, KeePassXC. Apple-only household → Apple is often enough. Zero budget + seriousness → Bitwarden free or KeePassXC if you own sync. Non-technical family → 1Password or Bitwarden Families often buy the comfort.
Free options: useful, clear limits
Browsers (Chrome, Edge, Firefox, Safari): zero friction, already there. Glued to a browser / account; family sharing often weak. For Chrome + Android only, still a huge upgrade over a notebook or Password1.
Google Password Manager (passwords.google.com): Google-account sync, strong suggestions, breach alerts. Limits: dependence on that account, less polished outside Chrome, more power in one giant. Honest for many — not ideal if you want distance from Google.
Apple Passwords / iCloud Keychain: excellent inside the Apple garden (sync, biometrics, passkeys). Add a Windows PC or Android phone and it cracks. All-Apple household → often the smoothest free choice.
Bitwarden free: generous open-source reference — unlimited items, sync, extensions, apps. Free pushes toward Premium for some advanced features (attachments, integrated TOTP depending on offer, families). For an individual with no budget, often the best seriousness-to-price ratio. Read their security docs, not only YouTube.
Beware obscure 4.9-star apps: a bad manager centralizes all your secrets. The downside is asymmetric.
Paid options: strengths and weaknesses
1Password — polished UX, Secret Key + master model, family/team sharing, solid security docs. Among the pricier options; you pay for comfort and adoption, not absolute guarantees. Strong when the family must actually stick with it.
Bitwarden Premium / Families — same open-source base, unlocked features, family/org plans, often lower price, self-hosting possible. UX good but less “premium design”; self-hosting only helps if you own backups and updates.
Dashlane — mainstream onboarding, alerts, sometimes a bundled VPN. The “all-in-one” perimeter can blur what you pay for; compare to real need (often: vault + sync + sharing).
KeePass / KeePassXC — encrypted file under your control, mature open source. No mandatory SaaS — but you own sync, backups, mobile clients. Excellent for technical profiles; high friction for a non-technical family. Not “safer” if the only file dies with the drive.
Proton Pass — privacy coherence in the Proton ecosystem, freemium then paid. Younger on some workflows: test autofill on your critical sites before migrating 200 entries.
None replaces MFA on your primary email.
When free is enough vs when paid makes sense
Free is often enough if you live in one ecosystem, you are alone on your accounts, you actually generate unique secrets, and the parent account (Apple ID / Google) has MFA.
Paying makes sense if you juggle Windows + iPhone (or Android + Mac), you need couple/flatshare sharing without pasting into chat, you want clear family recovery, or you prefer a vendor whose product is the vault.
Paying without changing habits (weak master, MFA off) wastes money. Well-used Bitwarden free beats poorly configured 1Password.
To place these tools in broader hygiene, see also /en/tools — without an affiliate storefront.
Migration in 30–60 minutes
- Pick (built-in for zero friction; Bitwarden for dedicated free; paid for family / multi-OS).
- Create a long master (5+ uncommon-word phrase). Enable MFA on the manager.
- Print / store offline the recovery kit the same day.
- Import the browser (official export) — then delete plaintext CSVs.
- Prioritize: primary email → bank / taxes → Apple/Google/Microsoft → shops with a saved card.
- For each priority: new unique secret, save, sign out dubious sessions.
- Everything else as you go. Day-one perfection is how people quit.
Check your email on Have I Been Pwned to prioritize — not to collect anxiety.
Passkeys: complement, not a total replacement
Passkeys (FIDO) tie a crypto key to your device / biometrics / manager. Against phishing, a fake site has a much harder time getting you to “hand over” a passkey like a password. Managers are also becoming passkey wallets.
Not universal yet. 2026 strategy: enable passkeys where offered (email, banks, major platforms); keep a manager for the rest; do not cut MFA “because passkey” without understanding account recovery.
Common mistakes
Short or reused master; no MFA on the vault; CSV export on the Desktop for months; sharing the master as a couple instead of a shared vault; ignoring recovery until the phone is in a puddle; migrating everything… except email; believing the manager replaces MFA; rotating every 30 days with no incident (fatigue, weak variants — change on doubt or breach, in the spirit of NIST / ANSSI).
10-minute action plan
- Enable saving / generation in your phone or browser (or create Bitwarden).
- Change the password on your primary email to a unique generated secret.
- Turn on two-step authentication on that email (authenticator app rather than SMS when you can).
- Tomorrow: import the browser, handle bank + app stores.
- For breach mechanics and the checklist: Why password breaches never seem to stop.
The goal is not a perfect fortress. It is to stop offering the same key to every lock.
Going further
- EFF — Creating Strong Passwords — length, uniqueness, tool.
- NIST SP 800-63 — modern framework for secrets.
- Have I Been Pwned — prioritize known dumps.
- Bitwarden Help / Security — security model.
- 1Password Security — design and white papers.
- Apple — Passwords / Google Password Manager — built-in options.
- FIDO Alliance — Passkeys — passwordless trajectory.
- ANSSI — French authentication guidance.
- Proton Pass — Proton privacy approach.
Sources
- Bitwarden — Help Center / Security
- 1Password — Security design / White papers
- NIST — Digital Identity Guidelines (SP 800-63)
- ANSSI — authentication / passwords
- Have I Been Pwned
- EFF — Creating Strong Passwords (Surveillance Self-Defense)
- Apple — Passwords / iCloud Keychain
- Google — Password Manager
- FIDO Alliance — Passkeys
- Proton — Proton Pass
Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us
Keep exploring
France Identité: useful tool or trap?
Official app tied to France’s credit-card-format ID, NFC, one-time ID proofs, FranceConnect / FranceConnect+, town-hall certification: what it really changes — and the risks (phone theft, dependency, exclusion).
Read the article →Tracking cookies: what the consent banner actually changes
Consent banners don’t “turn off the internet.” Here’s what accepting or refusing really changes, what it doesn’t, and how to stay in control.
Read the article →Why password breaches never seem to stop
Automated reuse of stolen logins, recycled passwords, the breach economy, managers, and passkeys (passwordless sign-in): why leaks keep coming back — and what actually works, without fearmongering.
Read the article →