
Two hundred and eighty-seven logins lived across a shared spreadsheet, a browser's autofill cache, and a graveyard of sticky notes before I moved a single one of them into a real vault. That number is the reason people ask me the same handful of questions whenever this site publishes anything about password security: how did you actually do it, what broke, and was it worth the mess. A HubSpot support email with a 'v' where a 'u' should have been is what started the whole project — close enough to fool a tired scroll, not close enough to survive a second look at the sender field. So instead of another blow-by-blow diary entry, here's the migration explained the way readers actually ask about it.
Quick disclosure, since we're already here: a few links below go to password managers I've tested and paid for myself, and if you sign up through one of them I earn a commission at no extra cost to you. That doesn't change which one I tell you to skip, and I will tell you which one to skip.
One mistyped letter, and everything changed
One mistyped letter is all a phishing-domain trick needs, and mine used exactly that: a domain that read correctly at a glance and fell apart the second I checked it character by character. I'd already had three separate arguments with our IT analyst, Davon Kearney, about why a shared spreadsheet of vendor logins was a bad system disguised as a good one — Davon's counter, after round two, was to route anything sensitive through Slack DMs with 'delete after reading' typed into the message. It didn't survive contact with reality: a deleted Slack message doesn't erase what's sitting in someone's notification preview or a screenshot taken thirty seconds earlier. We hashed out most of that argument over coffee near the Rainey Street Historic District, both of us equally unconvinced by the other's system.
Relying on a browser's saved-password list felt like a reasonable stopgap at the time, the same way leaving a spare house key with a neighbor feels fine until you can't remember which neighbor has it anymore. A dedicated vault does something a browser's storage doesn't: it separates the thing protecting your passwords from the thing you use to browse the internet, so a compromised extension or a synced-device mixup doesn't hand over everything at once. That distinction is what finally got me off the fence, more than any breach headline did.

Which vaults survived the tryout?
Four password managers made it onto my test laptop before I picked a winner, and two of them didn't make it past the first real use. LastPass was the incumbent by default, and it lost me the day its browser extension logged me out mid-form for the third time during a client call — I closed the tab and didn't reopen it. Dashlane's interface was fine, genuinely fine, but its autofill kept guessing wrong on our own CMS login page often enough that I stopped trusting it to get anything right unsupervised. Proton Pass and RoboForm both stayed in rotation longer: Proton Pass because the privacy angle appealed to the part of me that dislikes handing one company my whole digital life, and RoboForm because its form-filling handled checkout flows that trip up almost everything else.
Landing on one vault for good
1Password won the actual migration, mostly because the interface felt built for a person instead of a server admin. I kept circling back to my own notes on Proton Pass before deciding — its bundle is genuinely appealing if you already want mail and VPN wrapped into one subscription, but I didn't, and paying for features I wasn't using felt like the cable-bill creep I was trying to escape in the first place. RoboForm almost won on form-filling alone, though its interface still looks like it wandered out of an earlier decade of software design.
My whole testing setup lives in a converted spare bedroom in South Austin, standing desk and all: a personal laptop for actual work on one side, a battered second machine that exists purely to install and uninstall whatever vault I'm evaluating that week on the other. A corkboard hangs above the desk with sticky notes tracking which trial expires when, most of them curling at the edges by the time I get around to canceling anything.
A reader named Mira Szczepańska, a remote-work consultant in Chicago juggling more than forty client-portal logins without any IT department behind her, asked me something during the process that stuck: can you actually move a full vault from one provider to another without retyping every password by hand? Vault portability turns out to matter more than people expect until they're the ones staring down an export screen, and it's a big part of why I steer people toward apps with clean, standard export formats instead of proprietary lock-in. Mira's also the one who tends to flag a product update before it shows up in my own feeds, which is a strange kind of help to get from someone I've never met in person.
Is exporting a CSV really safe digital hygiene?
Most migration guides tell you to export a CSV from your browser and upload it to the new vault, and technically that works. Practically, it's the riskiest part of the whole process: that export is a plain-text file listing every secret you own, sitting wherever your downloads folder happens to be, and deleting it afterward doesn't guarantee it's actually gone. Emptying the recycle bin doesn't touch what's still cached in system memory or lingering on unused disk sectors, which matters more than people assume when the file in question is a password list instead of a stray screenshot. Good digital hygiene means treating that export file like something radioactive: move fast, verify the import worked, then get rid of it properly instead of just dragging it to the trash.
Before wiping the test laptop for good, I ran EaseUS Key Finder across it first, just to confirm nothing was still sitting in a browser cache or an old saved-session file I'd forgotten about. It's not a password manager and doesn't pretend to be — it's a one-time recovery pass for exactly this situation, checking what a machine still remembers before you hand it off or reformat it.
What breach monitoring turned up across my SaaS logins
Turning on breach monitoring after the migration was rougher than I expected. Watchtower flagged close to half of my accounts as reused, weak, or already compromised, and the worst offender was a password I'd used across four different SaaS logins because it was easy to remember and I'd never once been forced to change it. Credential stuffing is the attack that exploits exactly that habit — one breached site's password list gets tried against every other login you own, automatically, at a scale no human attacker could manage by hand. Reading that as a headline is one thing; watching your own dashboard light up red account by account is another.

Do you need to understand the encryption to trust it?
Not really, and I say that as someone with no cybersecurity background who still uses these apps every day. What's worth knowing in one sentence: most serious vaults encrypt your data with AES-256 encryption, and there's password-hashing math running underneath that — PBKDF2, if you ever see the term — that makes guessing your master password computationally miserable rather than quick. Zero-knowledge architecture is the piece that actually matters day to day: it means the company storing your encrypted vault never has the key to open it themselves, so a breach on their end hands an attacker encrypted noise, not your actual passwords.
The Secret Key is the part that stops feeling abstract the first time you sign into a fresh machine mid-migration and realize the master password alone won't get you in — you need that second string too, generated once and never meant to be memorized. Pair that with two-factor on top of a genuinely strong master password, not a clever variation of one you've used elsewhere, and the whole system holds up even if one layer fails.
What broke along the way
Nothing about the switch went perfectly. A two-factor reset locked me out of one account for most of an afternoon after I set up a new authenticator app and forgot to save the backup codes anywhere I could actually find them — a check I now do on every account before moving to the next one. Davon still texts me breach headlines at six in the morning with zero context, which is oddly how I first heard about more than one of the vulnerabilities I've since written about here.
The moment that actually stuck with me wasn't a dashboard notification. It was deleting the old shared password spreadsheet for good — one click, gone — and feeling a specific kind of relief I can only compare to finally shredding a drawer full of old utility bills you'd been meaning to deal with for a year. Nothing dramatic happened. It just stopped existing, and I stopped worrying about who still had the link.
Family sharing meant one dinner-table argument
Setting up shared vaults for the household turned into its own negotiation. My husband didn't want a new app to learn, full stop, and we had one genuinely annoyed dinner-table argument about it before he admitted the current system — him texting me for the streaming password every few months — wasn't actually working either. A family plan covering five users solved it, though shared-vault permissions took some explaining: everyone gets access to what's relevant to them, not a master key to every account I own, which is a distinction he hadn't considered until I laid it out.
The vault I'd actually recommend now
If you're staring at your own version of 287 scattered logins, start with 1Password and build the habit of checking breach alerts monthly instead of treating the vault as a one-time setup task. The actual switch cost is real — plan for an afternoon, not twenty minutes — but it's a fraction of what a single account takeover costs in time and stress. That HubSpot email with the one wrong letter is still the best reminder I've got for why any of this was worth doing.