Why it matters: Although not foolproof, password managers are one of the most secure ways to generate, store, and use passwords. However, switching between them can be tedious and, in some cases, open users to security risks. A new feature for Android devices simplifies the process while removing a crucial vulnerability.

Android users can now transfer passwords and passkeys between password managers via a new procedure managed by the operating system. The feature already supports most major password managers on Android 8 or later, with more to follow.

To start, download the password manager you intend to transfer your information to. Then, choose the option to import or copy data from another manager. Android will automatically detect other installed password managers and display which ones support the transfer. After tapping "Continue," you can review the information being moved before authorizing the transfer.

Outside of speed, the feature's main new benefit is that it requires no file downloads. Moving passwords between managers sometimes involves downloading an unencrypted text file that could be intercepted. Furthermore, transferring passkeys usually requires reassigning them one by one, which the new process handles automatically.

Also Read: Essential Apps to Install on Windows and macOS (Including Password Managers)

Google confirmed that Android password transfers currently support Google Password Manager, 1Password, Bitwarden, and Dashlane. More managers are expected to add support soon.

Security experts generally recommend password managers as the best way to generate strong, unique passwords, something many users still struggle with. As recently as last year, "123456" and "password" still ranked among the most popular passwords.

However, password managers do have vulnerabilities and have suffered breaches, which might prompt users to switch between them. Earlier this year, researchers found vulnerabilities in Bitwarden, LastPass, and Dashlane. Password managers tied to web browsers can be even riskier, as Microsoft Edge was found to be storing saved passwords unencrypted in memory. Furthermore, Dashlane fell to brute-force attacks in June, and hackers stole LastPass subscriber information (but not passwords) later that month.

Passkeys, which tie authentication to specific devices via PINs and biometrics without revealing sensitive information to servers, are considered more secure than passwords, but not perfect. In August, researchers published a method for stealing passkeys from Google Chrome's memory, and they can also be stolen along with browser sessions.