Quick answer: A password manager creates and stores a strong, unique password for every account. A passkey goes a step further and replaces the password entirely, using your fingerprint or face instead. Use both together where you can.

We get called out to homes across the Gold Coast pretty regularly where someone pulls out a notebook - usually a spiral one, occasionally something fancier - and slides it across the table so we can see their passwords. Sometimes there is a loose piece of paper folded inside it. Sometimes a Post-it or two stuck to the cover. It is incredibly common, and honestly it makes complete sense as a system right up until the moment it does not - which is usually when someone gets hacked, loses the notebook, or realises their email password has been the same since 2011 and is now on seventeen different websites.

We are not judging. We have seen this a hundred times. But the world of logging in online is changing fast - and if nobody explains it to you in plain English, you are going to get left behind while everything quietly moves on without you.

First: Why Passwords Have Always Been a Terrible Idea

Passwords were invented in the 1960s by a computer scientist at MIT, and they were a reasonable idea at the time - when approximately twelve people used computers and none of them were trying to steal your superannuation. The problem is that we are still using essentially the same system sixty-odd years later, except now there are billions of people online, criminal gangs whose entire job is guessing passwords, and data breaches happening so frequently that there is a website (haveibeenpwned.com - yes, that is real) dedicated entirely to telling you how many times your email address has already been stolen.

The average person now has over 100 online accounts. Nobody can remember 100 unique, strong passwords. So people reuse the same password everywhere, or they use something simple, or they write it on a napkin. And then one website gets hacked, and suddenly the criminals have the password you also use for your email, your bank, and your MyGov account. This is not a personal failing. This is an impossible system that was never designed for how we actually live.

8B+
Records exposed in data breaches every year globally
2,200
Cyberattacks happen every single day - one every 39 seconds
3 sec
Time to crack a simple 8-character password
81%
Of breaches are caused by weak or stolen passwords

The case against the napkin system, in numbers.

What is a Password Manager?

A password manager is an app - on your phone, your computer, or both - that remembers all your passwords for you. You only need to remember one password: the one that opens the password manager itself. Everything else lives inside it, locked up, automatically filled in when you need it.

Think of it like a very secure filing cabinet for your digital life. You unlock the cabinet with one key. Everything inside is organised, labelled, and waiting for you. The filing cabinet also generates new, random, unguessable passwords for you when you need them - things like Kx9#mP2!vQr7zL that no criminal on earth is going to guess, and that you never need to remember because the cabinet remembers them for you.

The ones we recommend to clients are Bitwarden (free, excellent, open-source), 1Password (around $4.99 AUD/month, extremely polished), and Apple's built-in iCloud Keychain if you are entirely in the Apple ecosystem. All of them work on iPhone, Android, Windows, and Mac. None of them require a university degree to operate.

Worth knowing: some security suites bundle a password manager in alongside other tools - Norton 360 and Dashlane both do this, folding in VPN and antivirus under the one subscription. If you are already paying for one of those, check whether you are sitting on a password manager you have never turned on.

Tip: If you are an Apple household - iPhone, iPad, and Mac - you already have a perfectly good password manager built in and it has its own dedicated app. It is called Passwords. Before you buy anything, open the Passwords app and have a look at what is already in there. Most people are surprised by how much it already knows.

Two-Factor Authentication: The Second Lock on the Door

Two-factor authentication - 2FA - is the six-digit code that gets sent to your phone when you log in somewhere. It exists because a stolen password alone is not enough if someone also needs your phone to get in. The accounts that absolutely need it are your email, MyGov, bank, superannuation, and PayPal - anywhere that getting hacked means real money lost, records accessed, or government services locked. Those get 2FA, full stop.

Everything else - your Coles shop, the spa booking app, the forum you joined once in 2019 - does not need the same treatment. A strong, unique password from your password manager is genuinely sufficient for low-stakes accounts. Focus the effort where the consequences are serious, and let the password manager carry the rest.

Heads up: Some scammers will call you pretending to be your bank or Optus or the ATO, and ask you to read out the six-digit code that just appeared on your phone. Do not do this. No legitimate organisation will ever ask you for that code over the phone. If someone asks for it, hang up.

So What Exactly is a Passkey?

A passkey replaces your password and your two-factor code in one go — there is nothing to remember, nothing to type. You just look at your phone or press your finger to the fingerprint scanner, and you are in. Behind the scenes, your device and the website do a quick handshake using two linked digital keys — one stays on your device, one lives on the website — and because your half never leaves your phone, there is nothing for a criminal to steal from a data breach.

Password vs Passkey

Passkey
Safest
Password + 2FA
Good
Password only
Risky
The napkin
No.
One tap to log in - no password, no code
Nothing stored on the website to steal
Syncs automatically to your new phone
Already supported by Google, Apple, PayPal, MyGov

Passkeys are already here - and they are genuinely simpler than what they replace.

Your passkeys are automatically synced through your Apple ID or Google account, so if your phone ends up at the bottom of the Nerang River, you sign into your new one and everything comes back with it. This is also why your phone's lock screen suddenly matters more than it used to - your phone is the master key now. A strong PIN or fingerprint is not optional, it is essential.

Google, Apple, Microsoft, and most major websites are already supporting passkeys. Your MyGov account supports them. So does PayPal. So does eBay. The napkin era is genuinely ending - not as a metaphor, but as a technical reality that is already here.

Tip: Next time Google, Apple, or a major website offers to save a passkey for you, say yes. Your device will walk you through it - usually it is just one or two taps. The website remembers that you have one, and the next time you visit, you just use your fingerprint or face. That is the whole process.

Putting It All Together and Securing Your Digital Life

We are not going to ask you to fix everything in one afternoon. That is how people panic and go back to the napkin. Instead, here is a sensible order of operations that has worked for dozens of our clients:

1

Choose one password manager and install it today

Bitwarden is free and works on everything. 1Password costs a few dollars a month and is slightly more beginner-friendly. If you are all-Apple, just use iCloud Keychain - it is already on your devices. Pick one, install it, and do not overthink it. The best password manager is the one you will actually use.
2

Lock your phone and secure your email - these two come first

If your phone has no PIN, no fingerprint, and no Face ID, fix that right now - it is the master key to everything else you are about to set up. Then go into your email (Gmail, Outlook, whatever you use), open the security settings, and turn on two-factor authentication.
3

Visit each important website and log in - let the manager do the saving

You do not need to enter everything manually (although you can). Just work through your important accounts one by one - bank, super, MyGov - logging in as normal. Your password manager will prompt you to save each one as you go. Within a week, the accounts that matter will all be in there without any dramatic bulk-entry.
4

Say yes when websites offer to set up a passkey

Google, PayPal, eBay, and MyGov already support passkeys. When you log in and they offer to set one up, accept. It takes about thirty seconds. From then on, logging in to that site means pressing your finger to your phone - no passwords, no codes, no napkins required.
5

Retire the napkin. Properly. With fire.

Not in the park. Not in the recycling. Not face-up in the kitchen bin where anyone can read them. If it helps, treat it as a small ceremony - you have earned it.

Five steps that take less total time than a single password reset spiral.

The Honest Bit About What Can Go Wrong

We do a lot of these setups for people across the Gold Coast - mostly seniors and retirees, though honestly the questions are pretty much the same regardless of age. Here are the straight answers to the ones that come up every single time. If you would like a hand setting yours up, it is a standard home tech support job.

The Worry Why It Comes Up The Actual Answer
Forgetting the master password If you forget it, are you locked out forever? Every reputable password manager has account recovery - a recovery code, a trusted contact, or email recovery. Set it up the day you install the app.
The company getting hacked LastPass had a breach in 2022 - it made the news and spooked a lot of people. Your passwords are encrypted with your master password, which the company never holds. They cannot hand over what they do not have. It is not the same as someone stealing your notebook.
Losing your phone with 2FA on it What happens to all those six-digit codes if the phone is gone? Text-message codes go to your number, not the device - get a new SIM and they follow. Authenticator app codes? Sync your passwords to the cloud or backup your authentication codes in the app.
Passkeys being too complicated It sounds technical, so it must need a manual and a weekend to figure out. It is literally just your fingerprint or your face. If you can unlock your phone, you can use a passkey.

Common concerns - and why none of them are a reason to go back to the napkin.

Passwords, passkeys, 2FA - none of it is magic, but it is all dramatically better than the system currently held together by sticky notes, optimism, and the solemn promise of "I'll sort it out properly later." Later is now. The setup takes an afternoon. And if at any point you get stuck, lose the plot, or just want someone to sit next to you while you do it - that is exactly what we are here for. Give us a shout and we'll sort it out together.