Hexento

Home · Guides · Password manager vs built-in

Cornerstone guide

Password manager vs built-in

Apple Passwords / iCloud Keychain and Google Password Manager are good enough for a lot of people. Dedicated managers earn their fee when your life doesn’t fit one ecosystem — or when sharing and recovery get real.

Last updated:

Affiliate disclosure: Hexento may later earn commissions from password-manager partner links. Built-in options have no affiliate path and can still be the correct recommendation. See disclosure · methodology.

The only question that matters first

Where do you type passwords every week? One phone + one laptop in the same vendor family is a different problem than “Windows work PC, personal Android, partner on iPhone, shared Netflix-and-utilities chaos.”

If you can’t answer that, don’t buy a yearly plan yet. Map devices for five minutes.

When built-in is the right call

Honest take: for a single-adult Apple household that already saves strong unique passwords in iCloud Keychain / Passwords, a paid manager is optional polish — not a moral requirement.

When a dedicated manager usually wins

Comparison dimensions (not brand ads)

Autofill reliability

Daily friction kills adoption. The “best” vault you fight with is worse than a good-enough one you’ll use.

Export / exit

Can you leave with a standard export? Soft lock-in is a long-term tax.

Recovery story

Lose the master password or phone — then what? If the answer is vibes, fix process before migrating 200 logins.

Sharing model

Item sharing vs full vaults; whether your partner’s OS is a second-class citizen.

Threat model realism

Most people lose to phishing and reuse, not cinematic nation-state vault cracks. Uniqueness + 2FA dominate.

Price ceiling

Free tiers often limit devices. Family plans can beat N× individual. Year-two pricing matters.

Migration without self-owning

  1. Turn on 2FA for email first — email is the skeleton key for resets.
  2. Export or review what’s already in the browser/OS manager so you know the mess size.
  3. Pick the destination with platforms + sharing constraints (hub or Pickguard).
  4. Import, then fix weak/reused passwords on high-value accounts (banks, email, Apple/Google ID, cloud storage).
  5. Store recovery codes / emergency kit offline. Not in the same vault alone; not in chat history.
  6. Only then uninstall or disable the old autofill to stop split-brain saves.

Skip a paid manager if…

Paid skip signals

Illustrative shapes (not a live ranking)

When people do need dedicated tools, the market usually collapses into a few shapes: polish/household UX, open-source / self-host adjacent, suite-bundled (already paying Vendor X), and budget freemium. We score those shapes on the checklist above — we don’t crown a permanent #1. Category examples and pending partner slots live on the password managers hub.

FAQ

Is saving passwords in the browser “unsafe”?

It’s far safer than reuse and sticky notes if the device is protected and the browser/OS account isn’t shared with random people. The failure mode is shared family PCs and unlocked sessions — not the concept of a browser vault.

Should TOTP live in the same manager as passwords?

Convenience says yes; compartmentalization says maybe no. For most households, one good manager with TOTP + a sound device lock beats a Rube Goldberg setup they’ll abandon. Higher-risk users may split factors.

What about passkeys?

Use them where sites support them. They’re not a reason to avoid a password manager yet — passwords remain widespread. Prefer tools that don’t fight passkey workflows on your devices.

Will Hexento always push a paid manager?

No. Built-in can win. That’s deliberate. See methodology.

Next

Password managers hub · Pickguard · When you don’t need a VPN