Moving Off Chrome's Built-In Password Manager (and Why You Might Not Want To)

Chrome already offers to save your passwords, fills them in automatically, and costs nothing. For a lot of people that is genuinely enough, and anyone telling you it's "insecure" is overselling. But there are three specific things it doesn't do — and if any of them matter to you, moving out takes about five minutes.

First, credit where it's due

Chrome's password manager gets the fundamentals right. Passwords are encrypted at rest, it warns you when a saved password shows up in a known breach, it generates strong ones on signup, and it syncs across every device you're signed into. Using it is meaningfully better than reusing the same password everywhere, which is what most people do otherwise. If you're currently in the "same password with a number on the end" camp, turning on Chrome's manager is a real upgrade and you should do it today.

The case for moving isn't that it's broken. It's that it's built to keep you inside one browser and one account.

1. By default, Google holds the key

This is the one most people don't know. In its standard configuration, Google Password Manager encrypts your passwords with a key stored in your Google account — which means Google can decrypt them. That's not a secret or a scandal; it's documented, and it's what makes "see all your passwords on the web" work.

You can change it. Google offers on-device encryption, and separately a sync passphrase, either of which takes the key away from Google. Both are opt-in, both are buried in settings, and the passphrase option comes with a hard warning: forget it and the data is gone for good.

The distinction worth internalising is between encrypted and zero-knowledge. Almost everything is encrypted. Zero-knowledge means the provider structurally cannot read your data even if it wanted to — because the key is derived from a password it never receives. Chrome's manager can be configured that way. It isn't by default.

2. It lives inside Chrome

Your passwords are available wherever Chrome is and you're signed in — which is a lot of places, and is genuinely convenient. It's also the boundary. Switch to Firefox or Safari, use a work machine with a locked-down browser, or want your passwords in a desktop app, and you're exporting a CSV or copying by hand.

The same boundary applies to what a password manager can hold. Chrome's stores passwords and passkeys. Two-factor codes, software licence keys, recovery codes, WiFi passwords, the PIN for the router — those live in a notes app or a screenshot, which is where password hygiene usually falls apart in practice.

3. Sharing gives away a copy you can't take back

Google added family sharing to Password Manager, so this is no longer a gap — but the shape of it matters:

  • It only works inside a Google family group, capped at six people. Sharing with a flatmate, a colleague, or a parent who isn't in that group isn't part of the model.
  • It rolled out on mobile and hasn't consistently reached desktop Chrome.
  • Most importantly: sharing copies the password into the other person's vault. Once it's there, it's theirs. There's no "un-share" that reaches back and takes it away.

That last point is the one that bites. Share the streaming account with someone, fall out with them a year later, and your only real option is to change the password and re-share it with everyone else — which is exactly the manual scramble a password manager was supposed to eliminate.

Moving out takes about five minutes

Whatever you switch to, the process is the same and it's less painful than people expect:

You don't have to delete anything from Chrome on day one. Leave it as a backup for a couple of weeks, confirm everything came across, then clear it out.

Where Spassword fits — and where it doesn't

Spassword is a free, zero-knowledge password manager for Chrome and Edge. Your master password is run through Argon2id on your device to derive the encryption key; the server only ever receives ciphertext, so we can't read your vault even if we wanted to or were compelled to. It holds passwords, two-factor codes, and passkeys in the same vault, and family sharing is per-item, end-to-end encrypted, and actually revocable — revoking re-encrypts the item with a fresh key and re-wraps it only for the people who still have access, so the person you removed can't use an old copy.

Being straight about the trade-offs, because you'll hit them:

If none of the three things above bother you, staying on Chrome's manager is a perfectly reasonable decision, and we'd rather you make it deliberately than switch because a blog post told you to.

Import your Chrome passwords in one step

Free Chrome & Edge extension. Zero-knowledge by design — we can't read your vault.

Get Spassword free
← Previous: Passkeys vs. Passwords Back to all posts →