631-905-9617    Get SUPPORT

Suffolk Computer Consultants Blog

Do Browser-Saved Passwords Stay Secure?

Do Browser-Saved Passwords Stay Secure?

One of the best things about computers is that there is always a new way to make something easier: automation decreases a workload, their processors can calculate much faster than the human brain can, collaboration with coworkers becomes almost effortless, and your web browser can even remember your passwords! However, you have to ask yourself: is the ability to save your passwords in your browser really a great idea?

In a Word: No
Unfortunately, there are ways that a hacker could access these passwords in each browser that the average user might use.

Google Chrome - When logged in to your Google account, Chrome automatically saves all of your passwords in that account. This means that all a hacker would need to do is gain access to your Google account, and they would be able to see all of your passwords, clear as day.

Mozilla Firefox - Firefox saves a user’s passwords under encryption, with the master password acting as the encryption key. However, this low-level encryption can easily be broken by a brute force attack. Furthermore, these passwords are also accessible by anyone in possession of the device without a login required.

Safari - Similarly to Firefox, all passwords are stored in the browser’s settings, and can be accessed without a login.

Internet Explorer - While IE saves your passwords, it does not show them… unless a relatively easy-to-find tool is utilized. Then your saved passwords are exposed.

Microsoft Edge - Microsoft Edge has had a few problems with security in the past, from the fact that there was a flaw in Edge that allowed hackers to read browser-compatible files (like notepad files, that some people might use to store passwords and credentials in). There have also been problems with some third-party managers in the past, like Edge Password Manager, also neglecting to require password authentication.

This is nothing new. An 11-year-old bug was discovered in the beginning of this year that enabled the theft of website credentials. This bug allowed the saved usernames (which were often just emails) and passwords to also be automatically entered into an invisible hidden form, unbeknownst to the user.

What Can I Do?
The first step you should take is to disable the password manager that is built-in to your browser. The method of doing so varies between them.

Google Chrome - Select the Chrome Menu from the toolbar, and select Settings. Scroll down and select Advanced, and under Passwords and forms, click Manage passwords. Under Auto Sign-in, turn the switch to the off position.

Mozilla Firefox - Find the Firefox Menu in the toolbar, and access Options. Then select Privacy & Security on the left, and under the Forms & Passwords header, deselect Remember logins and passwords for websites.

Safari - In the toolbar, click the Safari Menu. The select Preferences, Autofill, and deselect the following: Using info from my Address Book card, Usernames and passwords, Other forms.

Internet Explorer - Just stop using this one, and use one of the others instead. However, if you insist on using IE (or you have no choice), click into the Internet Explorer Menu found in the toolbar, select Internet Options, Content, and under AutoComplete, select Settings. Once there, deselect Forms and Searches, as well as User names and passwords on forms, clicking OK to finalize your changes.

Microsoft Edge - Select the Edge Menu from the toolbar, and then select Settings. Scroll down to locate View advanced settings. Deactivate Offer to save passwords (under Privacy and services) and deactivate Save from entries (under Manage passwords).

While it may be a pain to remember all of your passwords, there are much more secure options out there. For example, there are services like LastPass that more securely store passwords behind powerful encryption, and while they aren’t infallible, they are far better than what your browser offers.

For more assistance with managing your IT and its security, reach out to Suffolk Computer Consultants at 631-905-9617.

Tip of the Week: 5 Ways to Keep Your Data Safe
A Short Look at 2018 in Cybersecurity


No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Saturday, October 20 2018
If you'd like to register, please fill in the username, password and name fields.

Captcha Image

Mobile? Grab this Article!

QR-Code dieser Seite

Tag Cloud

Tip of the Week Security Technology Business Computing Best Practices Cloud Privacy Cybersecurity Network Security Managed IT Services Malware Tech Term Communications Backup Smartphones Productivity Microsoft Communication Business Hardware Hosted Solutions Passwords Hackers Browser Business Management Efficiency Google User Tips Android Outsourced IT Internet VoIP Ransomware Email Small Business Software Social Media Wi-Fi Save Money Alert Data Recovery Windows 10 Employer-Employee Relationship Cloud Computing Innovation Business Intelligence Applications Miscellaneous Saving Money Router Collaboration Internet of Things Computer Twitter Data Data Backup Smartphone Bandwidth Microsoft Office Data Management Managed IT Services Users Data Breach Phishing Settings Patch Management BDR Virtualization Vulnerability Mobile Device Blockchain Excel IT Support Mobile Devices Password Office Access Control Workplace Tips Network Automation Analytics Apps Government VoIP Marketing Gadgets IT Services Windows Cost Management IT Support Wireless Charging Business Continuity Physical Security Managed IT Service Remote Monitoring Website Data Protection Office 365 Gmail Tech Terms Law Enforcement Holiday Information WiFi Retail Cybercrime Virtual Assistant Scam Dark Web Spam Wireless Mobile Device Management Workers VPN Tip of the week Remote Computing Battery Chrome Computers Virus Cortana Word Artificial Intelligence Company Culture App Compliance Hacking Politics Networking Productivity Paperless Office How To Inventory Work/Life Balance Content Filtering Troubleshooting IT Management Sports Telephone System Proactive IT Touchscreen Edge Threat Gadget Travel Voice over Internet Protocol Dongle G Suite Information Technology Managed IT Big Data Tablet Processors Value Office Tips Automobile Telecommute Movies Botnet Reporting Lead Generation Mobile Security Printer Server Update Connectivity Remote Monitoring and Management Knowledge Microsoft Office 365 Laptop Printing Facebook Shortcut Live Streaming Entertainment Bring Your Own Device Biometrics Spyware Recovery Files Telephony Data loss Hard Drives Unified Communications Disaster Recovery Telephone Systems File Sharing Medical IT Operating System Cleaning Printers User Tip Outlook Network Attached Storage Streaming Media Maintenance Remote Support Analysis Google Drive Comparison Authentication Paper CrashOverride WhatsApp Amazon Technology Tips Server Hybrid Cloud Access HP Database Google Maps Voice over IP Staff RAM Remote Control User Security GDPR WannaCry Environment Two-factor Authentication Server Management Antivirus Downloads Hosted Solution Managed Service BYOD Specifications Authorization Ink Backup and Disaster Recovery Document Management Tactics Phone System eCommerce Websites Education Microsoft Teams Smart Technology Spam Blocking Business Technology Storage HIPAA e-waste Spotify Tech Support Telecommuting Trends Copy Apple SSD SaaS Multi-Factor Security Conferencing IT budget PowerPoint News Safety Plug-In Digital Internet Explorer Licensing Online Shopping Cables Hiring/Firing Managing Stress Email Management Sales Error Hard Drive disposal Staffing Millennials Machine Learning A.I. Paste iPhone IaaS Customer Relationship Management Fun Worker Competition Credit Cards Freedom of Information IP Address Television Emoji HaaS Customer Service Printer Yahoo Mobile Office Encryption Upgrade Unified Threat Management Domains Search Windows 10 Current Events Leadership Vendor Management Autocorrect Public Speaking Computer Care Avoiding Downtime Presentation Scheduling Net Neutrality Dark Data Lithium-ion battery Personal Information Samsung Emergency Augmented Reality Gaming Console Managed Service Provider Wireless Technology 5G Instagram IBM Quick Tips DDoS Scalability Hacker Money The Internet of Things Video Games Employer Employee Relationship Budget Synergy Regulation

Newsletter Sign Up