Quick answer: A password manager creates and stores a strong, unique password for every account. A passkey goes a step further and replaces the password entirely, using your fingerprint or face instead. Use both together where you can.
We get called out to homes across the Gold Coast pretty regularly where someone pulls out a notebook - usually a spiral one, occasionally something fancier - and slides it across the table so we can see their passwords. Sometimes there is a loose piece of paper folded inside it. Sometimes a Post-it or two stuck to the cover. It is incredibly common, and honestly it makes complete sense as a system right up until the moment it does not - which is usually when someone gets hacked, loses the notebook, or realises their email password has been the same since 2011 and is now on seventeen different websites.
We are not judging. We have seen this a hundred times. But the world of logging in online is changing fast - and if nobody explains it to you in plain English, you are going to get left behind while everything quietly moves on without you.
First: Why Passwords Have Always Been a Terrible Idea
Passwords were invented in the 1960s by a computer scientist at MIT, and they were a reasonable idea at the time - when approximately twelve people used computers and none of them were trying to steal your superannuation. The problem is that we are still using essentially the same system sixty-odd years later, except now there are billions of people online, criminal gangs whose entire job is guessing passwords, and data breaches happening so frequently that there is a website (haveibeenpwned.com - yes, that is real) dedicated entirely to telling you how many times your email address has already been stolen.
The average person now has over 100 online accounts. Nobody can remember 100 unique, strong passwords. So people reuse the same password everywhere, or they use something simple, or they write it on a napkin. And then one website gets hacked, and suddenly the criminals have the password you also use for your email, your bank, and your MyGov account. This is not a personal failing. This is an impossible system that was never designed for how we actually live.
The case against the napkin system, in numbers.
What is a Password Manager?
A password manager is an app - on your phone, your computer, or both - that remembers all your passwords for you. You only need to remember one password: the one that opens the password manager itself. Everything else lives inside it, locked up, automatically filled in when you need it.
Think of it like a very secure filing cabinet for your digital life. You unlock the cabinet with one key. Everything inside is organised, labelled, and waiting for you. The filing cabinet also generates new, random, unguessable passwords for you when you need them - things like Kx9#mP2!vQr7zL that no criminal on earth is going to guess, and that you never need to remember because the cabinet remembers them for you.
The ones we recommend to clients are Bitwarden (free, excellent, open-source), 1Password (around $4.99 AUD/month, extremely polished), and Apple's built-in iCloud Keychain if you are entirely in the Apple ecosystem. All of them work on iPhone, Android, Windows, and Mac. None of them require a university degree to operate.
Worth knowing: some security suites bundle a password manager in alongside other tools - Norton 360 and Dashlane both do this, folding in VPN and antivirus under the one subscription. If you are already paying for one of those, check whether you are sitting on a password manager you have never turned on.
Tip: If you are an Apple household - iPhone, iPad, and Mac - you already have a perfectly good password manager built in and it has its own dedicated app. It is called Passwords. Before you buy anything, open the Passwords app and have a look at what is already in there. Most people are surprised by how much it already knows.
Two-Factor Authentication: The Second Lock on the Door
Two-factor authentication - 2FA - is the six-digit code that gets sent to your phone when you log in somewhere. It exists because a stolen password alone is not enough if someone also needs your phone to get in. The accounts that absolutely need it are your email, MyGov, bank, superannuation, and PayPal - anywhere that getting hacked means real money lost, records accessed, or government services locked. Those get 2FA, full stop.
Everything else - your Coles shop, the spa booking app, the forum you joined once in 2019 - does not need the same treatment. A strong, unique password from your password manager is genuinely sufficient for low-stakes accounts. Focus the effort where the consequences are serious, and let the password manager carry the rest.
So What Exactly is a Passkey?
A passkey replaces your password and your two-factor code in one go — there is nothing to remember, nothing to type. You just look at your phone or press your finger to the fingerprint scanner, and you are in. Behind the scenes, your device and the website do a quick handshake using two linked digital keys — one stays on your device, one lives on the website — and because your half never leaves your phone, there is nothing for a criminal to steal from a data breach.
Password vs Passkey
Passkeys are already here - and they are genuinely simpler than what they replace.
Your passkeys are automatically synced through your Apple ID or Google account, so if your phone ends up at the bottom of the Nerang River, you sign into your new one and everything comes back with it. This is also why your phone's lock screen suddenly matters more than it used to - your phone is the master key now. A strong PIN or fingerprint is not optional, it is essential.
Google, Apple, Microsoft, and most major websites are already supporting passkeys. Your MyGov account supports them. So does PayPal. So does eBay. The napkin era is genuinely ending - not as a metaphor, but as a technical reality that is already here.
Tip: Next time Google, Apple, or a major website offers to save a passkey for you, say yes. Your device will walk you through it - usually it is just one or two taps. The website remembers that you have one, and the next time you visit, you just use your fingerprint or face. That is the whole process.
Putting It All Together and Securing Your Digital Life
We are not going to ask you to fix everything in one afternoon. That is how people panic and go back to the napkin. Instead, here is a sensible order of operations that has worked for dozens of our clients:
Choose one password manager and install it today
Lock your phone and secure your email - these two come first
Visit each important website and log in - let the manager do the saving
Say yes when websites offer to set up a passkey
Retire the napkin. Properly. With fire.
Five steps that take less total time than a single password reset spiral.
The Honest Bit About What Can Go Wrong
We do a lot of these setups for people across the Gold Coast - mostly seniors and retirees, though honestly the questions are pretty much the same regardless of age. Here are the straight answers to the ones that come up every single time. If you would like a hand setting yours up, it is a standard home tech support job.
Common concerns - and why none of them are a reason to go back to the napkin.
Passwords, passkeys, 2FA - none of it is magic, but it is all dramatically better than the system currently held together by sticky notes, optimism, and the solemn promise of "I'll sort it out properly later." Later is now. The setup takes an afternoon. And if at any point you get stuck, lose the plot, or just want someone to sit next to you while you do it - that is exactly what we are here for. Give us a shout and we'll sort it out together.