Where should your passwords live? Google, Apple or your own
Your password manager opens every other account. What Google and Apple's built-in options actually do, and when running your own vault is worth it.
First, the part that matters more than anything else in this article: use a password manager. Which one is a detail. Using none is the actual problem, and the built-in ones are free, already installed and work well.
If you are choosing, though, it is worth understanding what the choice is — because this is the one vault that opens all the others.
Who can open the box?
Encryption gets used loosely, and the difference that matters is simple: who holds the key.
If the provider holds it, your data is encrypted on their disks — genuinely useful, protects you if a drive is stolen or a datacentre is burgled — but they can open it. For support, for scanning, or if legally compelled.
If only you hold it, they are storing a sealed box they cannot open. Nobody can be made to hand over contents they do not have.
they hold the key
Encrypted on their disks
Genuinely useful. Protects you if a drive is stolen.
They can open it
For support, for scanning, or if they are legally compelled to.
A breach reaches the contents
Because the key is in the same building as the box.
only you hold the key
They store a sealed box
And have no way of seeing what is inside it.
Nobody can be made to open it
You cannot hand over contents you do not have.
Lose the key, lose the contents
This is the real trade, and it lands entirely on you.
For password managers specifically, the good news is that all the serious options — including Google’s and Apple’s — are built so the provider cannot read your passwords. This is one area where the industry got it right.
So the difference is not really “can they read it”. It is everything around it.
What the built-in options actually cost you
They tie you to an ecosystem. Apple’s works beautifully on Apple devices and awkwardly elsewhere. Google’s is at its best in Chrome. If your household runs a mix — and most do — you will hit the seams constantly, and the friction pushes people back toward bad habits.
Your vault depends on that one account. If your Google or Apple account is locked, disabled, or lost, the thing that opens everything else goes with it. Account lockouts are rare, and they are catastrophic when they happen, and there is often no human to appeal to.
You inherit their decisions. Features, sharing, what happens on a platform they stop supporting. Fine, until it is not.
Sharing barely works. Household sharing across two ecosystems is where most people give up and start messaging passwords to each other, which is worse than anything else discussed here.
What a self-hosted vault changes
Running your own — Vaultwarden is the common choice, and it works with the standard Bitwarden apps on every platform — changes three things.
The vault is yours. It lives on a machine you chose, in a country you chose. No third party can lock you out of it because no third party is involved.
It works everywhere equally. Apps for every phone and browser, and none of them care which ecosystem the rest of your life is in. In a mixed household this is often the real reason people switch.
Sharing actually functions. Household vaults, shared logins for the shared accounts, without anyone texting a password.
And because it is open source, anybody can inspect how it works. That is a weaker claim than people sometimes make — most of us will never read the code — but it does mean a great many people have, and problems get found and published rather than staying quiet.
The part that should worry you
You are now the recovery process.
Lose the master password and the recovery material, and the vault is gone. Not “gone until support helps” — gone, permanently, by design. That is the same property that stops anyone else opening it.
Lose the server without a backup and you have the same outcome.
This is the whole trade, and anyone who glosses over it is selling something. Complete control means complete responsibility, and for some households the honest answer is that a big provider’s recovery process is worth more than the independence.
If you do it, do these
- Write the master password down on paper and put it somewhere you keep important documents. Not a file. Paper. This advice sounds wrong and is right — the realistic threat to your vault is you forgetting, not a burglar searching your filing cabinet for a password.
- Save the recovery material the same way, separately.
- Back the vault up automatically, somewhere that is not the machine it runs on.
- Test a restore. An untested backup is a belief, not a backup.
- Tell one other person where those pieces are, if anyone would need your accounts should something happen to you.
The straight answer
Using nothing is the actual emergency. Fix that today with whatever is already on your phone.
Google or Apple’s built-in manager is a good choice if your household lives in one ecosystem and you would rather somebody else carried the recovery problem. That is a legitimate, sensible position.
Your own vault is the better answer if you run a mix of platforms, want household sharing that works, or find it genuinely uncomfortable that one account you do not control holds the keys to everything else.
The deciding question is not really about security — all three options encrypt properly. It is: who do you want holding the ability to lock you out? A company, or only yourself.
Both answers are defensible. Only one of them is a decision you have actually made.