
My browser's autofill just sits there, blank, refusing to drop anything into the login box in front of me. The site is hubsp0t.com — a zero standing in for the o — and for one dumb half-second the address bar looks completely normal until my eyes catch it. That's the exact trick that almost cost our whole marketing ops team its SaaS stack years ago: a look-alike domain built to catch someone moving too fast to check. This time the browser caught it before I did, which says something about password security that no training session ever managed to: sometimes the software is smarter than the habit.
Here's the required heads-up before I go further: some of the links below are affiliate links, the tools I actually kept paying for out of my own card long after the free trial ended. Click through and buy something, I earn a commission, you pay the same price either way. Full details live on my About page, and nothing here got written because a company sent me a free year of anything.
Is My Browser's Save-Password Prompt Actually Protecting Anything?
It's the question I started asking seriously after that HubSpot phishing scare, and the short answer is: only while your laptop itself is locked. Chrome and Safari store your credentials in a file that stays effectively unlocked the entire time you're logged into your Windows or Mac profile — no separate password, no extra prompt, nothing standing between someone at your desk and every account you've ever saved. A dedicated vault works differently: it needs its own master key to open, separate from your OS login entirely, and it locks itself back up after a few idle minutes whether you remember to or not. That's the entire pitch behind something like 1Password: two separate locks stacked on top of each other instead of one.
I tested this myself, on the spare laptop I keep just for trying out new apps. Selected everything Chrome had saved, hit export, and had a finished CSV of every login sitting on my desktop in under thirty seconds — no master password, no second factor, nothing standing in the way. It felt like discovering my bank's vault door was actually made of drywall.

Your IT Team Still Wants a Shared Spreadsheet, and Here's Why That's a Problem
Davon, our IT analyst, is the one who still argues for keeping shared logins in a spreadsheet, and he's got the department policy memorized well enough to quote the exact clause that supposedly requires it — dropped into casual conversation like it's small talk, not evidence. I get the instinct behind the paper trail. I don't get the execution: a spreadsheet has exactly one lock, whoever remembers to restrict sharing on the file, and that lock fails the moment someone forwards a copy "just for reference."
A real vault doesn't have that failure mode built in the same way. Your master password is the one credential you're supposed to actually remember and never reuse anywhere else — not a variation on whatever you use for your OS login, not a pattern anyone could guess by watching you type twice. I used to have exactly that kind of pattern for work logins before the HubSpot scare: same base word, one symbol bumped up each time a site forced a reset, HubSpot1! turning into HubSpot2! like I was leveling up a character instead of protecting an account. It worked right up until it didn't. Some vaults go a step further and pair that master password with a separate secret key generated when you first set up the account, so even if someone somehow learned the master password alone, they'd still be missing half the combination.
Does Syncing Through Chrome or Apple Actually Help on Sketchy Wifi?
Here's the one place I'll go against most of the security advice floating around: browser-level sync between your phone and laptop sometimes rides on more robust infrastructure than a dedicated vault's own sync protocol. When Chrome or Safari sync your saved logins, they're using Google's or Apple's identity backbone, the same pipes handling billions of other accounts. A vault app syncing over public wifi at a coffee shop in the Domain Northside is using its own proprietary connection instead, which is usually solid, but it's still a smaller target with less infrastructure behind it than what Google or Apple run.
I noticed this while comparing RoboForm's sync against 1Password's during a testing stretch: RoboForm leans harder into browser-adjacent syncing, and it never once hiccupped over the sketchy public networks I threw at it. That's a narrow advantage though, and it disappears the second you're on a private network, which for a marketing ops job juggling client extranets is most of the day.

Zero-Knowledge Encryption and the AES-256 Number Everyone Throws Around
Zero-knowledge encryption is the part that actually won me over, once I understood what it meant in practice: the company hosting your passwords has no way to read them, ever, even if their servers get hacked tomorrow. If Proton Pass got breached, whoever broke in would find scrambled data they can't do anything with, because they never had my master password to begin with. The actual cipher behind that is AES 256 encryption, a whole separate rabbit hole I won't fully unpack here, except to say it's the same math trusted to lock down financial and government systems, not just password apps.
My dad asked, predictably, why we couldn't just keep using the Notes app on his phone once I tried explaining zero-knowledge to him over a family plan comparison. I told him it's the difference between writing a credit card number on a postcard and sealing it in something that needs a second, separate key to open — one is a suggestion of privacy, the other is closer to a guarantee. Proton Pass also bundles in email aliases through Proton Mail, so a marketing inbox drowning in newsletter signups can hand out a disposable alias instead of a real address, which is its own small win against phishing.
What Actually Made Me Give Up on Bitwarden?
Bitwarden is the one that didn't survive contact with an actual work week for me. The security fundamentals are solid and the price is hard to argue with, but getting our small team properly set up meant hand-configuring collections and permission groups until it felt like homework, right in the middle of a launch crunch when I needed people added in minutes, not sorted into a spreadsheet of their own. I gave up on making it the team default and went looking at heavier, more polished options instead.
Moving away from it wasn't really a loss, though. Every dedicated vault I've tried supports a real export and import, so the actual credentials didn't need re-entering by hand. Vault portability turned out to matter more than any single feature: the ability to leave a provider without losing years of saved logins is what makes trying a new one low-risk in the first place.
Moving Fifty-Plus Logins Without Losing a Launch Week
Actually switching took an afternoon, not the multi-day ordeal I'd braced for. Export from the old tool, import into the new one, then go back and manually clear whatever's still cached in the browser itself — skip that last step and you've just built a second, unlocked copy of everything you were trying to protect. 1Password's Watchtower feature was the thing that actually kept me honest afterward, flagging weak or reused entries across all fifty-plus logins and telling me flat out when one turned up in a breach I hadn't heard about yet.
Passkeys and two-factor codes live inside the vault too now, instead of scattered across text messages and a browser's separate settings page, which sounds like a small change until your phone dies during a work trip and you need a second factor that doesn't depend on that specific device. Travel Mode is the feature I didn't know I needed until a marketing conference made it relevant: it temporarily hides whichever vaults you choose, so crossing a border with a work laptop doesn't mean carrying every client credential you own in your bag.
Mira Szczepańska, a reader who runs her own remote-work consultancy without any IT department behind her, asked me once whether an emergency kit is really necessary for a one-person operation. She keeps her own running changelog of every setting she's changed across the vault apps she's tested, so when I told her to set up an emergency kit, the printed backup that gets you back into your account if your phone and laptop both vanish at once, she'd already half-built her own version of one. For anyone without an IT team as a safety net, that backup matters more, not less.
For personal accounts, I've stayed with Proton Pass mostly because I already live inside their email ecosystem and didn't want to manage two separate identity providers. And since the whole reason any of this started was a scammer finding my name and title in the first place, I've kept Incogni running quietly in the background to get my information pulled off the broker sites that hand it to anyone willing to pay for it.
The Real Credential Hygiene Fix for Marketing Ops Teams
None of this requires becoming a security person overnight. Four years into running marketing ops for a company that adds new SaaS tools every quarter, I've watched our login count balloon well past fifty, and the actual fix turned out to be narrower than it looks: pick one dedicated vault, move your accounts over in an afternoon, delete the browser copies once you've confirmed the import worked, and stop reusing patterns you can predict yourself. That's the whole credential hygiene fix for a marketing ops team drowning in SaaS logins, not a security overhaul, just moving the keys off the doormat and into something that actually locks. If you're starting from zero, 1Password is still where I'd point a coworker first, mostly because it's the one that never made me want to throw a laptop during a launch week.