> ## Content Index
> Fetch the complete content index at: https://blog.techstreamlined.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# How My Password Manager, TOTPs, Passkeys, and Autofill Help Keep Me Safe Online
- URL: https://blog.techstreamlined.com/how-my-password-manager-totps-passkeys-and-autofill-help-keep-me-safe-online/
- Published: 2026-08-31T15:00:00.000Z
- Updated: 2026-08-31T14:59:59.000Z
- Description: As an independent managed services provider, I often sign in to more websites in an hour than most people do in a week. Without a reliable password manager and browser extension, the lost time - and the security risk - would quickly become a frustrating inconvenience.
- Author: Ari Footlik

### Introduction

Before password-management apps and web-browser plug-ins, I did what many people did: I saved usernames and passwords in Excel files, spiral-bound notebooks, and unlabeled sticky notes. It worked, mostly, until my growing number of accounts and the need for secure storage and access demanded something better.

Today, as an independent managed services provider, I often sign in to more websites in an hour than most people do in a week. Some are my own accounts; others are client-provided accounts. Without a reliable password manager and browser extension, the lost time - and the security risk - would quickly become a frustrating inconvenience.

I currently use and recommend Bitwarden as my password manager/vault, but the ideas in this article apply to most contemporary, reputable password managers.

While evaluating the features of various password-management tools, I came across an excellent post by James Cridland that addressed a question I had been considering, and a practice I had been avoiding: Does storing time-based one-time-password information, or TOTPs, in the same vault as the related password undermine the security benefit of multi-factor authentication?

In James Cridland’s article, “Should you store your 2FA/TOTP tokens in your password manager?” *(*<https://james.cridland.net/blog/2021/should-you-store-your-2fa-totp-tokens-in-your-password-manager/>*)*, the author acknowledges the tradeoff. Keeping passwords and TOTP information separate creates another layer of protection if the vault is compromised. But keeping them together can make secure habits much easier to adopt and maintain: passwords and codes are available across your multiple devices, synchronized through one trusted service, and easier to recover when a device is replaced or lost.

For many people the convenience, availability, and greater likelihood of actually using MFA/2FA/TOTP outweigh the tradeoff of storing those alongside passwords, provided the vault itself is protected by a unique master password and strong, separate MFA.

A capable, properly configured password manager can add a layer of security to everyday sign-in habits.

### First, Protect the Vault!

Your password manager/vault contains keys to nearly every important part of your online life. Guard it like your personal, digital Fort Knox!

Use a long, unique master password that you don’t use anywhere else. Protect the password manager with MFA, preferably using a passkey or even a physical security device which, if supported, can facilitate even stronger protection of such a critical asset.

Save the password manager’s recovery information securely, too. Identify and plan how you would regain access if your computer or phone were replaced, damaged, lost, or stolen. Also be sure you understand options for backup, account recovery, and secure transfer to another password manager.

### Passwords, TOTP, and Passkeys

Security analysts used to advocate for long, complex passwords using a mixture of characters and symbols, and of course, people would write these down in unprotected places. Guidance changed to using long passwords that were easy for you to remember but difficult for someone else to guess. But without a password-manger, password-reuse was epidemic.

Since the password manager does the remembering, it takes little extra effort to use a unique password for every site and account. Many password managers offer features to help generate long, complex passwords, and can also help create and manage TOTP codes. As previously mentioned, keeping codes alongside their associated password is convenient, but it concentrates more risk into the vault, which is why protecting the vault is so important.

For more background see my related article, “Understanding MFA, 2FA, and TOTP.”

Passkeys raise related but slightly different questions. A password manager that supports passkeys can simplify sign-ins and synchronize passkeys among your devices. Before selecting a primary passkey vault, however, understand its recovery, backup, and secure-transfer options. My article, “Passkeys: A Simpler, Safer Way to Sign In,” can help clarify how passkeys slot into your security toolkit.

### Use the Tools!

A password manager is more than a secure list of passwords. Its browser extension can help you save new credentials, find existing ones, and fill them only where they belong. Some can store Wi-Fi codes, credit-card numbers, personal stats… We can better leverage the password manager if we keep the following in mind when populating it with accounts, passwords, and data.

**Save new logins carefully and intentionally**

Enable the password manager’s option to offer to save new passwords, if your product provides one. After successfully creating or signing in to an account that is not already in the vault, the browser extension may offer to save the login.

Before saving, review and edit the data being saved:

- Give the entry a clear name or description that you’ll recognize later
- Double-check the username or email address is correct
- Confirm the correct password entered in the right field
- Verify the saved website-address is of the intended, legitimate site where the login belongs

Pay particular attention to the address being saved with the credential, as that data drives the autofill functionality.

Folders, collections, or tags can also make a vault easier to manage. They are especially useful when you have several accounts for one service, like a personal Microsoft account, a work Microsoft 365 account, and your guest-login to partner-organization’s Microsoft environment.

**Let Autofill Be a Safety Check**

A browser extension uses the website-address saved with a login item to decide when and which credential to offer. In Bitwarden, saved login items need an associated website-address for autofill to work. Bitwarden can compare the current site with that saved address using different matching settings. This is useful for convenience, but it can also be a security signal.

When you visit a familiar site and autofill is enabled, your password manager should normally offer the expected login. Depending on your app or settings, you may need to select the saved credential or use a keyboard shortcut to fill it. But if the expected login is not offered, stop before typing anything further and check the address bar carefully.

A missing autofill suggestion does not necessarily indicate a site is fraudulent. The saved address may be incomplete, the site may use a 3rd-party authentication system, or the saved website-address or settings may be too restrictive. The missed autofill is a good reason to pause and verify where you are, and to perhaps refine the saved data so autofill works as expected on the next visit.

Don’t casually click “Yes” if prompted to add a new website-address to an existing, saved login just to make autofill work. First confirm that the website is legitimate and the same credentials are applicable. A password manager should help you avoid entering a real password into an unknown site, not train itself to trust a bad site.

### **Typo Squatting: A Useful Example**

“Typo squatting” is the practice of registering a domain name that is very similar to a well-known one. The goal may be harmless, intended purely as humor or commentary. More often, the goal is to catch people who mistype an address or fail to notice a subtle difference in a fraudulent link.

Imagine receiving an email that appears to be from Amazon. The message includes a link that takes you to “arnazom.com.” The page you reach may look convincing. It may show a familiar logo, product images, and a login form. If you are entering passwords manually, you might attempt several possible credential combinations before noticing anything is wrong. The malicious website could capture each of those attempted credentials.

Now consider the same situation with a password manager.

You arrive at the site, but your password manager does not autofill your saved Amazon login. That does not automatically prove the page is fake, but it gives you a reason to stop. You inspect the address bar, notice the misspelling, and close the page without entering anything.

That pause may have prevented a serious security incident!

### Make Security Easier to Use

The best tool shouldn’t be judged on the number of steps involved. The right password manager is one you can understand, maintain, and use consistently.

Using a password manager certainly helps keep things organized, removing the need to remember dozens of passwords. A tool with TOTP support makes it easier to use MFA when passkeys are not available. Passkey support can reduce the need for passwords altogether for websites that support it.

But none of these tools obviate the need for careful judgment and scrutiny. You should still be critical of unexpected messages, avoid following unsolicited links, and protect your password manager, email accounts, sensitive records, and mobile-carrier account especially well.

When your passwords, TOTP codes, passkeys, and browser extension are properly configured, they work together to make safer online habits easier to #streamline into your workflow.