Every guide here is about the cleanup after a breach, not everyday password hygiene.That is a deliberate narrowing. Advice on picking a strong password is everywhere and mostly fine. Advice on what to actually do at 11pm with forty exposed logins and no idea where to start is not.
NIST agrees with the narrowing. SP 800-63-4 says verifiers SHALL NOT force scheduled password changes, and SHALL force one when there is evidence of compromise. Rotating on a calendar is theatre. Rotating because your password is sitting in a breach dump is the thing everyone agrees on.
Bar length is how long you have, not how many accounts.
The four-tier priority order, four time estimates that disagree with each other by a factor of ten, a tracker sheet you can download, and what to do when a password change fails halfway and locks you out of your own account. That last section exists because no other guide has it.
1 of 11 can do it today, and a second is announced but not shipped.
Both are locked to a single ecosystem. No shipping product does it on any site, on any platform.
First-party benchmark. Every vendor claim checked against its own documentation, with dates and sources for every row. Includes why Dashlane built this feature, shipped it to more than 500 sites, then quietly removed it, and why Google and Apple have both limited theirs to lists they control.
What actually happens to your data when a password manager has a bad day, and what a tool has to guarantee before it touches your credentials.
In research
When your password manager is breached, what is actually exposed?
Being written now. It is the only unpublished topic on this page, because it is the only one that has cleared our own bar for demand: roughly eighteen independent posts asking it in six weeks, none of them ours.
Free tools
All three run entirely in your browser. Nothing you type is sent to a server, and there is no signup on any of them.
Four rules, and they are the reason there are two guides here rather than twenty.
01A topic has to earn its place. Nothing gets written until enough people are independently asking about it. Our own posts never count as evidence.
02Primary sources, linked. Standards, regulations and vendor documentation are quoted and linked so you can check the wording yourself rather than take ours.
03When a number does not exist, we say so. Nobody has measured how long a breach cleanup takes. The guide prints four conflicting estimates and labels all four as unmeasured rather than picking a confident one.
04Our own product sits inside the comparison, not above it. Rekey appears in the manager table as a row like any other, marked as in development and not counted in the eleven.
Written by Alex McComas while building Rekey, an open-source password tool. The code and a written security review are public, so you can check any of it yourself.
Get the tool that does the boring part
Rekey is a browser extension, in development. It finds every exposed login, takes you to the change page for each one, and keeps your old password in the vault until the new one is confirmed working. Join the early-access list and we will email you once, at launch.