A Password Manager for a Household

0
17
A teenage girl sits on a couch with headphones, looking at a smartphone.
Photo: Karolina Grabowska / Kaboompics, via Pexels. Pexels License.

A password manager is a program that makes a different long password for every account and remembers them for you. You remember one passphrase for the manager. The Cybersecurity and Infrastructure Security Agency, CISA, says that is one of the easiest ways to stop someone from logging into your accounts and taking money, data, or your identity. A notebook in a kitchen drawer is safer than reusing one password. A manager is safer than the notebook, because it can also fill the password in so you are not typing it where a stranger can see.

This guide is for a household: a parent, a teen, an older adult, and the adult child who helps set it up. It does not name a product to buy. CISA says some managers are built into the browser and some cost money, and it points people to a trusted review such as Consumer Reports rather than to one brand. Checked September 25, 2026.

What “strong” means

CISA says a strong password does all three of these things:

  • Long. At least 16 characters. Longer is stronger.
  • Random. Not a birthday, a pet, or the word “password.” CISA’s two options are a random mix of letters, numbers, and symbols, or a passphrase of four to seven unrelated words. “HorsePurpleHatRunBay” is their example of a stronger passphrase. Spaces are allowed if you want them.
  • Unique. A different password for each account. The bank, the email, and a social app should not share one.

CISA’s example of what goes wrong is simple enough to repeat. A person used the same password on email and on the bank. A company breach posted that password. Someone moved money. The bank password reset went to the email, and the email used the same password, so the reset was useless. Hours on the phone followed. A manager does not make a breach impossible. It keeps one leaked password from opening the next account.

Do not save the list in a file on the computer named “passwords.” CISA says not to. Do not put the list in an email to yourself. Email is the account that resets everything else.

Set up one vault, then decide who else gets a key

  1. Pick a manager you install from the official app store or from the company’s own website. Not from a search ad, and not from a text. CISA says to read reviews and choose a reputable program. Browser managers count. A paid one is fine if you will actually use it. An unused subscription protects nothing.
  2. Create the vault passphrase with CISA’s rule: at least 16 characters, or four to seven unrelated words. Write that one passphrase on paper and store the paper with the birth certificates, not on the fridge. This is the password you cannot ask the manager to remember.
  3. Turn on multi-factor authentication for the manager itself, then for email, bank, and health accounts. CISA says not to forget MFA, especially on email, social accounts, and financial accounts. MFA means a second check, such as a code or a prompt, after the password. A stolen password alone should not be enough.
  4. Add email first. Then the bank. Then the school portal and the health portal. Then stores and apps. The manager will offer a generated password when you change each one. Let it. Do not “improve” the generated password by adding the child’s name.
  5. Delete the old reused password as you go. If a site will not accept a long password, that is a weakness in the site. CISA says you can ask them why. Use the longest unique password that site allows, and turn on MFA there.

A parent and an older adult can share one family vault if they trust each other with every login in it. Say that out loud. A shared vault is shared access. It is not a secret from the other person. An adult child who sets this up for a parent should put the parent’s email in as the recovery contact, and should show the parent how to open the vault on the day you install it. Leaving town with the only passphrase is how a parent gets locked out of the electric bill.

A teen should not live inside the parent’s vault forever. Give them their own vault when they have their own email. You can know the recovery method without reading every login every night. Their school password should not be yours, and yours should not be theirs. Phone setup for a first phone is a separate job. Account limits are in Screen Time and Family Link.

What to put in the vault, and what to leave out

  • Put logins: email, bank, school, health, shopping, and the Wi-Fi password if the manager has a notes field you trust.
  • Leave out the child’s Social Security number unless the manager has a secure notes feature you have decided to use, and unless the paper copy is already locked up. A freeze on the child’s credit is still worth doing. That guide is how to freeze a child’s credit.
  • Do not store the vault passphrase inside the vault. That defeats the one thing you have to remember.
  • Do not tell a caller the passphrase, a one-time code, or a password from the vault. A bank, the school, and tech support will not ask you to read those aloud. A code request on the phone is the same family of scam as a gift card. See gift cards are only for gifts and fake tech-support pop-ups.

Sit with an older adult for the first three accounts

The first session should be short. Install the app. Make the passphrase. Add email and the bank. Turn on MFA. Stop. A two-hour tour of every store login ends with a frustrated person writing passwords on a sticky note anyway.

Show three things and no more:

  1. How to open the vault with the passphrase or with the face unlock you turned on.
  2. How a login fills in, so they do not retype a password a shoulder-surfer can watch.
  3. Who to call if the app asks for the passphrase and they did not open it themselves. The answer is you, not the number on the screen.

If they already reuse one password, change email and the bank first. Those two are the ones in CISA’s example. The gardening forum can wait.

What to skip

  • Do not install a “password manager” from an ad that appeared after you searched. Use the store or the company’s site.
  • Do not keep using the old password “as a backup” on the bank. Unique means the old one is retired.
  • Do not share the vault passphrase in a family text thread. Say it in person, or store the paper copy. A text thread is not a safe.
  • Do not turn off MFA because the codes are annoying. CISA lists MFA next to the manager for a reason. The manager holds the password. MFA is the second lock.

Checklist

  • The manager came from an official store or the company’s own site.
  • The vault passphrase is at least 16 characters, or four to seven unrelated words, and it is written down somewhere safe.
  • MFA is on for the manager, email, bank, and health accounts.
  • Email and the bank no longer share a password with each other or with anything else.
  • A teen’s school login is not the parent’s vault password.
  • An older adult has practiced opening the vault once, without you holding the phone.
  • Nobody in the house will read a vault code to a caller.

What this means for you

A parent should set the family vault up before a child has a stack of app accounts, not after a breach email. The manager will not raise a child. It will keep one leaked app password from opening the email that resets the bank.

An adult child helping a parent should leave the recovery email pointed at the parent, or at a shared family address both of you can open. If the only recovery path is your personal inbox, you have become a single point of failure.

A grandparent who will not use an app can still stop reusing one password. CISA’s passphrase of unrelated words is something a person can remember for the two accounts that matter, while a manager covers the rest when they are ready. Do not shame the paper list. Move the important accounts off the reused password this week.

FAQ

Is a browser’s built-in password saver good enough?

CISA says built-in browser managers are one of the free options. They are better than one reused password. A separate manager is useful if you use more than one browser or more than one kind of phone and want the same vault on all of them. Pick the one you will actually open.

What if I forget the vault passphrase?

That is the one password the manager cannot reset for you unless you set up recovery when you created it. This is why the paper copy exists, and why a second trusted adult should know where it is. Do not store that copy in the email account the vault protects.

Should a child know the parent’s vault password?

No. Give a teen their own vault and their own email. A younger child does not need the family bank password. If they must use a school site, put that one login on their device, not the whole vault.

Does a manager stop someone who already has my email?

Not by itself. Change the email password from a device the other person is not watching, turn on MFA, and then change the bank. CISA’s example starts with a reused password. Unique passwords plus MFA are the recovery, after you have the email back.

Sources

Photo: a teenage girl using a smartphone, by Karolina Grabowska / Kaboompics, via Pexels. Pexels License.

This is not legal or financial advice. CISA does not require a specific brand of password manager. If a site’s password rules have changed, follow that site’s current page.

Update this guide if CISA changes the 16-character guidance, or if it stops recommending password managers for families.

Previous articleSchool Apps: What Parents Can Ask
jugglingchaos
As a digital marketing professional with a passion for innovation and project management, I am highly motivated, educated, with diverse marketing and technology experience. I have a proven track record of success in driving business growth and change, from start-ups to billion-dollar publicly traded companies. Building strong business relationships comes naturally to me, and I am comfortable presenting to all levels of an organization, clients, and the public. I possess exceptional negotiation skills and excel at problem-solving, mediation, and mentoring. I am skilled in achieving organizational, individual, and team goals with balance and integrity.

LEAVE A REPLY

Please enter your comment!
Please enter your name here