Skip to main content

Why you should never allow your web browser to save your passwords


Why you should never allow your web browser to save your passwords



When a web browser like Chrome, Firefox or Safari is allowed to store passwords, you're putting your network security at risk.







One reason why you shouldn't allow your web browser to save your passwords
Passwords. They are the bane of so many users' existence. Yet, they're one of the only ways we have to secure our accounts, and those accounts are frequently compromised. IT pros always harp on users to create secure passwords--to the tune of creating password profiles that demand specific requirements.
And yet, no matter how hard we try to lock down those accounts, they are still vulnerable.

Why?

First off, even after being constantly warned, users still insist on passwords like 12345 or password. Even when those users employ incredibly complex passwords, there is still a roadblock in the way of enjoying a truly safe networking experiencing. Said roadblock is when a web browser is allowed to store passwords.
Sure, it's convenient. After all, who wants to type a password every single time it's requested? When you make use of a large number of online services, typing a password each time you use said service can disrupt your productivity. And when those passwords are incredibly complex, such that you must use a password manager, efficiency goes out the window.
And yet, even at the expense of productivity, there's a very good reason why you should never allow a web browser to remember your passwords. That reason is how easy it is to view passwords in modern web browsers. Chrome will allow users to view passwords, even without requiring a master password. Firefox, on the other hand, at least requires a master password, but only if one is set (which many users either overlook or aren't aware of its existence). Like Firefox, Safari at least hides passwords behind a user's password. The difference between Firefox and Safari is the password isn't optional in Apple's browser.

How easy can you view saved passwords?

Update: If you're using the Windows 10 platform, you will be prompted for a user password, in order to access saved passwords in Chrome.
Let me demonstrate how easy it is to view saved passwords on the three browsers mentioned. Remember, this only works on passwords that are stored by the browser. First, we'll look at Chrome (as it is the most vulnerable). To view saved passwords in Chrome, do the following:
  1. Open Chrome.
  2. Click the Menu button and select Settings.
  3. Scroll to Autofill and click Passwords.
  4. Locate the password you want to view and click the "eye" icon (Figure A).
  5. Enjoy that password.





Figure A
Figure A: Viewing a stored password in Chrome.

To do the same trick in Firefox, do the following:
  1. Open Firefox.
  2. Open the Menu and select Preferences.
  3. Click Privacy & Security (from the left pane).
  4. Scroll to Logins & Passwords.
  5. Click Saved Logins.
  6. Click Show Passwords (Figure B).
  7. Enjoy your passwords.





Figure B
Figure B: Viewing stored passwords in Firefox.

The only caveat to the steps in Firefox is if a Master Password is in use. Should that be the case, you'll be prompted for that password, after clicking Show Passwords. Without the Master Password, you cannot view stored credentials.
Now, let's examine Safari. Here are the steps for viewing passwords in Apple's browser.
  1. Open Safari.
  2. Click the Safari menu in the top bar and select Preferences.
  3. Click the Passwords tab.
  4. When prompted either type your password, or use the fingerprint sensor (if available).
  5. Click on the website you want to view (Figure C).
  6. Enjoy that password. 


Figure C
Figure C: Viewing stored passwords in Safari.

Clearly, Safari has the edge here, only because it requires the use of a password to view stored credentials. If Firefox stored credentials are locked by a Master Password, then it puts the Mozilla browser on similar ground. As far as Chrome is concerned, your saved passwords are there for all to see, unfettered and unprotected.

What to do?

The answer to this question is simple. Don't allow your browser to save your passwords. None of them. Not one. If you do, those passwords are vulnerable. All someone has to do is have access to your computer (remote or physical) and, unless you use Safari or the Master Password feature in Firefox, those passwords are available for anyone to see.
If you absolutely must have your browser store your passwords, and you're not using macOS, make sure to use Firefox and enable the Master Password feature. Use Chrome at the peril of your passwords.
In place of having your web browser store your passwords, make use of a password manager. By doing so, the likelihood of someone viewing your passwords is considerably lower. It's not perfect, but it's far better than handing over the security of your passwords to a web browser.
The adage, "Better safe, than sorry," most certainly applies.

Also see


Comments

Title

Link

https://amzn.to/3isoLUX https://www.amazon.in/gp/product/B082PFY9S7?smid=AT95IG9ONZD7S&psc=1&linkCode=sl1&tag=mywebsit0749e-21&linkId=5108a27204271760a5ba4d6108af7893&language=en_IN&ref_=as_li_ss_tl https://amzn.to/3ist5DR https://amzn.to/3s5ZcMQ

Information security policy

Information security policy To protect your information assets, you need to define acceptable and unacceptable use of systems and identify responsibilities for employees, IT staff, and supervisors/managers. This policy offers a comprehensive outline for establishing rules and guidelines to secure your company data. From the policy: Employee responsibilities An employee who uses the company workstations or systems to conduct business operations must:  Ensure that all equipment use is for business/professional reasons. Access only information that is needed to perform their jobs or assist others in doing so as part of the valid scope of their duties. Be responsible for the content of all data, including text, audio, and images they share internally or externally. All communications should have the employee’s name attached. Be responsible for all actions/transactions performed with their accounts. Use passwords and screen locks on company-owned systems or devices, or those

How to cloud-enable Enpass Password Manager

How to cloud-enable Enpass Password Manager Learn how to combine Enpass and Dropbox into a perfect, cloud-ready password manager. 0:00 Fullscreen We've reached a point in time where very strong (non-memorizable) passwords should no longer be considered an option. Because of this, I tell everyone I advise to use a password manager that includes a random password generator so that the chances of someone hacking into one or more of their accounts are lessened exponentially. One of the password managers that ticks off nearly all of my boxes is  Enpass . It's cross-platform (available for Linux, Android, iOS, macOS, and Windows), has a great password generator, and (best of all) can be made cloud-ready. Must-Read Cloud Google Cloud Platform: An insider’s guide (free PDF) It's that last option that really seals the deal for me. Because of this, I can link every instance of Enpass I

New Amazon class certifies cloud pros in securing data on AWS

New Amazon class certifies cloud pros in securing data on AWS The AWS Certified Security - Specialty Exam could help tech professionals broaden their skills on the AWS platform. 0:00 Fullscreen Building a slide deck, pitch, or presentation? Here are the big takeaways: A new class from Amazon, the AWS Certified Security - Specialty Exam, will validate a cloud pro's ability to secure the AWS platform. Cloud skills are in high demand, but added security expertise could help set job seekers apart. A new professional exam from Amazon Web Services (AWS) will help cloud experts validate their ability to secure data on the platform, according to a  Monday blog post . The  AWS Certified Security - Specialty Exam  is now available to those who hold either an Associate or Cloud Practitioner certification from AWS. As noted in the post, AWS recommends that those taking the exam have at least five years

Some Hot New Technologies That Will Change Everything

Some Hot New Technologies That Will Change Everything Illustration: Randy Lyhus The Next Big thing? The  memristor , a microscopic component that can "remember" electrical states even when turned off. It's expected to be far cheaper and faster than flash storage. A theoretical concept since 1971, it has now been built in labs and is already starting to revolutionize everything we know about computing, possibly making flash memory, RAM, and even hard drives obsolete within a decade. The memristor is just one of the incredible technological advances sending shock waves through the world of computing. Other innovations in the works are more down-to-earth, but they also carry watershed significance. From the technologies that finally make  paperless offices  a reality to those that deliver  wireless power , these advances should make your humble PC a far different beast come the turn of the decade. In the following sec

Network security policy

Network security policy This policy will help you create security guidelines for devices that transport and store data. You can use it as-is or customize it to fit the needs of your organization and employees. From the policy  Summary Every company’s network is made up of devices that transmit and store information. This can include internal and external systems, either company-owned or leased/rented/subscribed to. To protect company data and reputation, it is essential to ensure that the network is secured from unauthorized access, data loss, malware infestations, and security breaches. This must be done via systematic end-to-end controls. Policy details The IT department will be responsible for implementing, adhering to, and maintaining these controls. For the purposes of this document, “all devices” refers to workstations, laptops, servers, switches, routers, firewalls, mobile devices, and wireless access points. Where possible, these guidelines will app

Top Java Interview Questions You Must Prepare In 2019(java interview questions and answers for freshers)

Top Java Interview Questions  You Must Prepare In 2019(java interview questions and answers for freshers) Java is today the most trusted language across the global developer community. With nearly all of the Fortune 1000 companies running applications on the Java Virtual Machine (JVM), Java has become a legendary language. Even while new languages and technology closely related to Java are popping up every now and then, they leverage capabilities of the JVM in some way. It is almost certain that Java will never go out of fashion. A career in Java will open up multiple opportunities in a wide range of job roles. We have curated a list of definitive Java questions that will help you breeze through your interview. In case you have attended Java interviews yourself or have any questions that you want us to answer for you, do feel free to add them as comments below. 1. What are the principle concepts of OOPS? Principle Concepts of OOPs Concept Description Abstraction Abstra

Google I/O 2019 schedule includes sessions on Stadia, dark mode, lots of Assistant, but no Wear OS

Google I/O 2019 schedule includes sessions on Stadia, dark mode, lots of Assistant, but no Wear OS Google I/O is one of the most exciting times of the year for us tech nerds, and as we near the 2019 event,  the schedule is now up for all to see . This isn't the full complement of sessions — many smaller talks and workshops will be added in due course — but it does give us a good idea of which areas Google is likely to focus on most this year. It all kicks off on May 7 at 10am with the Google Keynote at the Shoreline Amphitheatre where Sundar will talk us through some of Google's key goals for the year ahead, followed by a more developer focussed keynote. The rest of the first day is packed with sessions on gaming, Material Design, self-driving cars, Android, and a number on Assistant. The  3pm deep dive into the streaming tech behind Stadia  could be particularly interesting. There's also  a talk about building apps for foldable displays . Day two starts wit