Keyring is a private demonstration page, not a password manager, and is not affiliated with any company. No product is named or recommended on it.
Password managers
Almost nobody is breached because their password was too short. They are breached because one site leaked it and twenty others accepted it. A manager exists to make every password different — which is a thing no human memory can do, and the only thing that actually closes this off.
Why reuse is the problem
This is what credential stuffing is: attackers take a username and password from one breach and try the pair everywhere else, automatically. It works because most people reuse.
Leaked from one forum in 2019
Summer2019!
Long enough. A capital, a number, a symbol. It passed the site's strength meter — and none of that matters once the site itself is breached and the pair is published.
The arithmetic
Every character you add multiplies the number of possibilities; swapping an o for a 0 does not, because the software guessing knows that substitution. These are categories, not stopwatch figures — anyone quoting you exact crack times is guessing at hardware.
P@ssw0rd!
Falls immediately
It is a dictionary word with the substitutions every cracking tool tries first. The symbols buy essentially nothing because the pattern is the most common one there is.
Tr0ub4dor&3
Falls quickly
Harder, and still built from one word plus decoration. It is also impossible to remember, which is why people write it down or reuse it — the practical failure rather than the mathematical one.
kitchen-radio-9
Reasonable for a low-value account
Three unrelated elements, easy to recall, no substitutions. Fine for a forum. Not what you want on email or banking.
copper lantern drift almanac
Strong, and memorable
Four random common words. Long, no symbols, and you can actually hold it in your head — which is what makes it a realistic choice for the one password you must remember: the manager's own.
This matters for exactly one password. Every other password you own should be long, random and unmemorised, because the manager types them. Spend your memory on the master.
Moving to a manager is the part people abandon halfway. This is the order that works, including what to do about the accounts you have forgotten.
Before you switch
The trade is real and worth naming: you are putting every credential behind one secret. A page that recommends this without saying so is not being straight with you.
Reuse, completely
Every site gets a different password because you never have to remember any of them. This is the whole benefit, and it is a large one.
Phishing, partly
A manager fills credentials by matching the site address. On a lookalike domain it simply will not offer them — which is a better phishing check than human attention.
The forgotten-account problem
The vault becomes a list of every account you have, which is the only practical way to find and close the ones you stopped using.
Everything behind one secret
If the master password is guessable, or written where someone finds it, the concentration works against you. It has to be long, unique and never used anywhere else.
Recovery into one path
Most managers cannot reset your master for you — that is the point of the design. Losing it can mean losing the vault, so the recovery kit is not optional paperwork.
Protect an already-breached account
Changing a password after a leak matters, but if someone is already inside with a session or a passkey, the password is not the only thing to revoke.
How to choose
Ignore the feature grids; the differences that matter are about architecture and exit, not how many fields the notes editor has.
The phrase to look for is end-to-end or zero-knowledge encryption: the provider stores a blob it cannot read. If a service can show you your own passwords through a support agent, it can also be compelled to.
Check this before you import a single login. A manager that makes leaving hard has a lock-in incentive, and you will want to move at some point.
Some offer an emergency kit, some a trusted contact, some nothing at all. Whichever it is, set it up on day one — not the day you need it.
Published audits and open-source clients are not guarantees, but they are the only external evidence you get. Prefer specifics over the word “bank-grade”, which means nothing.
Passkeys are gradually replacing passwords on major sites, and a manager that stores both is the difference between one place to look and two.
Your browser's built-in manager is a legitimate starting point and much better than reuse. Its limits are cross-browser use and sharing — if neither matters to you, it may be all you need.
Straight answers
Go straight to the source
One email, then we leave you alone
The order that works, what to do with forgotten accounts, and the two things to set up on day one rather than the day you need them.