Each of our favorite Android phones comes with Google’s built-in password manager.
It offers a convenient, secure way to store your credentials and is better than relying on your memory to enter the single password you use everywhere.
While it is convenient, Google’s built-in tool isn’t a great password manager. It wouldn’t be our default recommendation, even if you’re just starting with a proper password management system.
Here are the main reasons to avoid Google Password Manager and choose better third-party alternatives.
All hail the Chrome ecosystem
Your passwords don’t move from browser to browser
The Google Password Manager doesn’t have its own app — it lives inside the Chrome browser on your computer and Play Services on your phone.
That arrangement works fine for Android phones because the Play Services are preinstalled and support autofill across websites open within any browser and app.
But on other platforms, you have to use Chrome because your passwords are saved in it — so no other browsers for you.
For example, you’d need to install and set Chrome as your autofill app to access your passwords on an iPhone, since it doesn’t have access to Play Services.
Meanwhile, on your computer, Chrome can autofill your credentials only on websites; for other apps installed on your PC, you’ll have to copy and paste your passwords.
If Google’s password manager had a standalone app you could install on your computer, it would’ve saved you from relying on the browser all the time.
But that would also break the Chrome lock-in, which isn’t a wise business decision for Google.
Are your passwords protected?
Are you sure?
To access your passwords in Google Chrome on an Android phone, you need to authenticate yourself using your biometrics.
That’s about as secure as it gets, but you can also unlock your passwords with your phone’s PIN.
If someone gains access to your PIN, like was famously reported in iPhone theft cases last year, your passwords stored in Chrome are only as secure as your lock screen PIN.
Third-party password management apps usually require you to set up a complex master password separate from any other service as a fallback when biometric recognition fails.
But in Google’s case, the password manager is connected to your Google account.
So, you must remember your account password, which you cannot store in the password manager, and setting up a memorable password for your primary Google account risks all your passwords, or … there’s no other option.
Additionally, if one day Google decides to disable your account for any random policy violation like it has unfairly done to a few people, you will have difficulties recovering your passwords.
You may be able to retrieve local copies of your saved credentials, but that depends on which devices you use and how up to date the synced copies are.
Not as feature-rich
Dedicated password managers are far ahead of the game
While Google Password Manager is good enough for basic use, it lacks many tools and features you often find on dedicated alternatives, even on their free tiers.
For instance, most modern managers support 2FA code autofill within the app. That helps you keep everything organized in a single app while still including the second authentication factor.
Password managers typically let you customize new passwords they generate to suit your (and the site’s) needs, but Google doesn’t offer that kind of tinkering.
While family sharing was added recently, it still lacks advanced features like timed sharing, setting restrictions, or sharing items with people outside your family — all of which are supported by other password managers.
Many of us also like to use the extra security of password managers to store sensitive documents such as identity cards and more, but Google’s version doesn’t offer such storage options.
Those are stored within Google and on Android, but through separate features, and not through Google Password Manager.
While that may not necessarily be a bad thing, it makes finding specific details more difficult.
Security concerns
Data encryption isn’t enabled by default
The biggest selling point of Google Password Manager is its ease of use and lower barrier to entry even for people who aren’t technically inclined.
But instead of providing proper safety from the get-go, Google doesn’t enable on-device encryption by default. That means your username and passwords stored in its password manager could be more easily extracted from Google servers, whether by bad actors or the company.
To enable on-device encryption, you must go into the password manager’s settings, which lives within Chrome’s settings menu. People who aren’t aware of this option will be left exposed to security concerns.
On Chrome for Windows, some tools could read browser data, including your passwords stored in Chrome, even if data protection is enabled.
That’s one solid reason to switch away from any browser-based password manager right away to a real one.
Best Google Password Manager alternatives you can check out
I agree that Google Password Manager has the lowest barrier to entry of all password managers, but that slight initial effort will go a long way.
For instance, you’ll get a proper cross-platform experience and won’t be locked into the browser’s ecosystem.
Plus, dedicated password managers are more secure since they’re made from the ground up to store your most sensitive data and aren’t affected by various browser vulnerabilities.
My personal password manager of choice is Enpass since I’m on its grandfathered Enpass Pro subscription.
One of its biggest benefits is that I get to choose where I want to save my password vault. For everyone else, I’d recommend Bitwarden. It has been one of our favorite password manager recommendations for a long time now, and it deserves to be there for its rich free tier, while its open source nature is the cherry on the cake.
Besides that, 1Password has proven to be a reliable alternative, with a nice interface and additional security features that make it worth the price.
Whichever password manager you choose, it is important in this day and age that you use one.
Using a password manager and setting up two-factor authentication on all your accounts will eliminate a bulk of cyberattacks that are only getting more common by the day.


