Switching Password Managers in 2026

Switching Password Managers in 2026

2026 年更换密码管理器指南

Important Note: Although I work at Apple in the password management and app/website authentication spaces, in this post I am speaking only for myself, personally. There is no “news” in this post or any kind of “inside scoop”. Please do share this post, but if I see “Apple’s Ricky Mondello” anywhere, I’ll be sad. My intention is to help people benefit from data portability and interoperability work I’ve personally participated in. Nobody should feel locked into their password manager. :)

重要提示: 尽管我在苹果公司从事密码管理和应用/网站身份验证领域的工作,但本文仅代表我个人观点。文中没有任何“新闻”或所谓的“内幕消息”。欢迎分享这篇文章,但如果我看到任何地方称我为“苹果公司的 Ricky Mondello”,我会很难过。我的初衷是帮助大家从我个人参与的数据可移植性和互操作性工作中受益。没有人应该感到被困在某个特定的密码管理器中。:)

Would you believe me if I told you that the best device to switch password managers on might be your iPhone or iPad? For many pairs (exporter and importer) of apps, it’s true! Here’s a simultaneously boring and exciting video of me exporting 100 items from 1Password and into Apple Passwords.

如果我告诉你,更换密码管理器最好的设备可能是你的 iPhone 或 iPad,你相信吗?对于许多应用组合(导出方和导入方)来说,这确实是真的!这里有一段既枯燥又令人兴奋的视频,展示了我如何将 100 条数据从 1Password 导出并导入到 Apple Passwords 中。

To export from 1Password’s iOS app, navigate to Items › Settings › Advanced › Start Export. After approving the export, an iOS system interface confirms the data transfer request with Face ID and has me select the destination app. I pick “Passwords” (Apple Passwords), confirm my selection, and then Passwords opens to import the data. The data that’s exported from 1Password and imported to Apple Passwords includes passwords, passkeys, verification codes, notes, and more. No data is deleted from 1Password as part of the export. Apps that support this mechanism include Apple Passwords, 1Password, Bitwarden, Dashlane, DuckDuckGo, Devolutions, and more.

要从 1Password 的 iOS 应用导出数据,请导航至“项目 (Items)” › “设置 (Settings)” › “高级 (Advanced)” › “开始导出 (Start Export)”。批准导出后,iOS 系统界面会通过 Face ID 确认数据传输请求,并让我选择目标应用。我选择“密码 (Passwords)”(即 Apple Passwords),确认选择,随后 Passwords 应用会自动打开并导入数据。从 1Password 导出并导入到 Apple Passwords 的数据包括密码、通行密钥 (passkeys)、验证码、备注等。导出过程中不会从 1Password 删除任何数据。支持此机制的应用包括 Apple Passwords、1Password、Bitwarden、Dashlane、DuckDuckGo、Devolutions 等。

You might be wondering how a mobile operating system (of all places!) got data interoperability for password managers that’s easier, more secure, and more comprehensive than on desktop. You can thank passkeys and the passkey community for this. (But wait — didn’t you read on X or Hacker News that passkeys are just a trojan horse for platform and password manager vendor lock-in? Weird!)

你可能想知道,为什么移动操作系统(竟然是移动端!)能实现比桌面端更简单、更安全、更全面的密码管理器数据互操作性?这要归功于通行密钥 (passkeys) 和通行密钥社区。(等等——你难道没在 X 或 Hacker News 上看到过说通行密钥只是平台和密码管理器厂商锁定用户的“特洛伊木马”吗?真奇怪!)

I gave a keynote at the Identiverse conference this last June that, in part, tells the story of how delivering data interoperability for passkeys necessitated a bunch of standardization and innovation that’s made the password manager interoperability story better for everyone. (Here’s a timestamped YouTube link to the relevant portion, starting at 24:48.)

今年 6 月,我在 Identiverse 大会上发表了主题演讲,其中一部分讲述了如何通过实现通行密钥的数据互操作性,推动了一系列标准化和创新,从而改善了所有人的密码管理器互操作性体验。(这是相关部分的 YouTube 时间戳链接,从 24:48 开始。)

Transcribed, the story: Back in 2022, when passkeys were first made available on iPhone, one of the most important bits of feedback that the community gave Apple was: “Are these my credentials? My credentials that I can move between apps like passwords and a password manager? Or are they locked to wherever I initially saved them?” The answer to this was easy. Your credentials are yours to take and manage in whatever software you want, on whatever platform you want, whenever you want. We just needed to figure out how to enable that in a phishing-resistant way.

故事梗概如下:早在 2022 年,当通行密钥首次在 iPhone 上推出时,社区给苹果最重要的反馈之一是:“这些是我的凭据吗?是我可以在密码和密码管理器等应用之间移动的凭据吗?还是说它们被锁定在了我最初保存它们的地方?”答案很简单。你的凭据属于你自己,你可以随时随地在任何软件、任何平台上获取和管理它们。我们只需要弄清楚如何以一种防钓鱼的方式实现这一点。

At the time, the state of the art for transferring credential data wasn’t great. I’m talking about manually exporting an unencrypted file and then importing it into another app. And I think you all know that was going to be a non-starter for passkeys because a threat actor could trick someone into exporting their data and then uploading it to them. That’s called phishing. For data interoperability for passkeys to maintain their phishing-resistant promise and their ease of use, we were gonna need to work together and innovate as an entire community.

当时,传输凭据数据的技术水平并不理想。我指的是手动导出未加密的文件,然后再将其导入到另一个应用中。我想大家都知道,这对于通行密钥来说是行不通的,因为攻击者可以诱骗用户导出数据并上传给他们。这就是所谓的钓鱼攻击。为了让通行密钥的数据互操作性能够保持其防钓鱼的承诺和易用性,我们需要整个社区共同努力并进行创新。

And so, some folks within the FIDO Alliance started working on a concrete data format and requirements around transfer. In May of 2024, the first draft of the Credential Exchange format was published. That format, which is now published as an open spec that anyone can read, covers not just passkeys, but all of the rich data that you’ll find in a modern credential management app. At Apple, we started building on top of that work. And as of iOS 26 and macOS 26 released last fall, passkeys are now securely transferable between credential manager apps on Apple’s platforms. And that’s through a first-class mechanism that was built specifically for those apps.

因此,FIDO 联盟内的一些成员开始致力于制定具体的数据格式和传输要求。2024 年 5 月,凭据交换格式 (Credential Exchange format) 的首个草案发布。该格式现已作为开放规范发布,任何人都可以查阅,它不仅涵盖了通行密钥,还涵盖了现代凭据管理应用中常见的所有丰富数据。在苹果公司,我们开始基于这项工作进行开发。随着去年秋季发布的 iOS 26 和 macOS 26,通行密钥现在可以在苹果平台上的凭据管理器应用之间安全传输。这是通过专门为这些应用构建的一流机制实现的。

Here’s how it works. In the first app, you select the data that you want to export, and then you initiate a system export. In a secure, isolated, and out-of-process picker, you choose which of the registered other apps you want to transfer that data to. Then you Face ID, and you’re done. The data is transferred directly between the two apps that you have trust of, without any intermediate files being created.

其工作原理如下:在第一个应用中,你选择要导出的数据,然后启动系统导出。在一个安全、隔离且独立于进程的选择器中,你选择要将数据传输到的已注册应用。然后通过 Face ID 验证,就完成了。数据直接在你信任的两个应用之间传输,不会创建任何中间文件。

Then What? A data transfer starting on an iPhone or iPad is genuinely a fantastic start, but I recommend thinking about switching password managers as a process. You can use the relatively rare and potentially disruptive event of switching password managers as a reason to clean house a bit. Back in September of 2024, I wrote a piece titled “Consider Slowing Down When Switching Password Managers” about this, but I’m going to summarize and update my advice in this post so you don’t have to go back and read that one.

接下来做什么? 在 iPhone 或 iPad 上启动数据传输确实是一个很棒的开始,但我建议将更换密码管理器视为一个过程。你可以利用更换密码管理器这一相对罕见且可能具有破坏性的事件,作为清理数据的好机会。早在 2024 年 9 月,我就此写过一篇题为《更换密码管理器时请放慢脚步》的文章,但我会在本文中总结并更新我的建议,这样你就不必回头去读那篇旧文了。

My tips: If you’re fortunate enough to be able to, upgrading your phone is a great time to switch password managers! Many apps will, annoyingly, make you re-sign in. You can use that as an opportunity to stress test your new setup. You might also be in a mood to rearrange your apps, refresh your settings, and generally tidy up. I recommend you: Do your bulk transfer from your old app to your new app on your existing device, as described above, before you get your new device. Going forward, treat your new app as the source of truth for your information, and only consult the old app if something goes wrong. Do not spend time updating or deleting information from the old app; it’s only there as a safety net. Don’t try to keep multiple password managers in sync; with today’s technology, that’s folly. On your existing device, turn on AutoFill for your new app and turn off AutoFill for your old app.

我的建议: 如果你有条件,升级手机是更换密码管理器的绝佳时机!许多应用会很烦人地要求你重新登录。你可以利用这个机会来压力测试你的新设置。你可能也正好想重新整理应用、刷新设置并进行全面清理。我建议你:在拿到新设备之前,先在现有设备上按照上述方法将数据从旧应用批量传输到新应用。此后,将新应用视为你信息的唯一来源,只有在出现问题时才去查阅旧应用。不要花时间去更新或删除旧应用中的信息;它只是作为一个安全网存在。不要试图保持多个密码管理器同步;以今天的技术水平来看,这是愚蠢的。在现有设备上,开启新应用的自动填充功能,并关闭旧应用的自动填充功能。