SecurityGarden

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, August 7, 2013

The Danger of Saved Browser Passwords

Posted on 5:57 PM by Unknown

Chrome
As illustrated by the articles provided as examples in the references below, the hot topic in tech news today is the way the Google Chrome browser stores saved passwords.  Any passwords saved on the browser are visibly accessible by anyone with access to the computer via chrome://settings/passwords.

Yes, the key is that someone has to have access to your computer in order to see the passwords.  However, with light-weight laptops, netbooks and tablets, people are more likely than ever before to take their device even on excursions to the library, local coffee shop or diner.  Leave the device unlocked and untended for minutes and even if the device is not missing, someone could have easily had access to your Chrome passwords in plain text.

What?  You say your e-mail, bank and credit card company passwords aren't saved.  Unless you use a very complex and unique password for those venues, how long do you think it will take to figure out those passwords?

Then, there is the shared family computer.  Even if family members are set up with separate Standard User Accounts (see reference), how often do you walk away from the computer without logging off?  It isn't that we don't trust our children, but we may not know all of their friends or they may think it a funny joke to go to your favorite web forum and post some silly nonsense. 

Don't a lender or a borrower be also applies to your computer.  In the event you do agree to let a friend or family member borrow your computer, either enable the guest account or create a Standard User Account for their use. 

What about Firefox?

Firefox
Correct.  With Firefox, clicking Options > Security >Saved Passwords > Show Passwords reveals site passwords in plain text just like Chrome.  The major difference between the two, however, is that Mozilla provides a simple mechanism to create a Master Password.

After creating a master password, you will be prompted to enter it once when accessing your stored passwords.  Granted, it will also be necessary to enter the master password when you agree to Firefox remembering a new password, removing a password but your security is certainly worth that effort.

Most importantly, the master password will be needed for each Firefox session for each time you show your passwords.  So, if you do walk away from your computer, no one will be able to access your passwords.

Password Managers

Another option that is available for users of any browser, regardless of whether the password is visible or saved is a password manager program.

With a password manager, it does not matter which browser you use.  All passwords are secured. Rather than saving passwords to your computer, with a password manager, you only need to remember one password to access everywhere.
  • 1Password (Licensed $49.99 USD)
  • KeePass Password Safe (Free, open source)
  • LastPass (Free and premium version available)
  • RoboForm Password Manager (Free for 10 Logons, Licensed version available)

References

  • Chrome's Password Security Strategy Is Insane
  • Do you save passwords in Chrome? Maybe you should reconsider
  • Google Chrome policy exposes user passwords on purpose: Here's how to prevent it
  • MozillaZine Knowledge Base: Master password
  • Using a Standard/Limited User Account

Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Email ThisBlogThis!Share to XShare to Facebook
Posted in Browser, Security | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • How to use Hotmail Aliases
    Whether shopping online, joining an on-line tech forum, registering your account for on-line bill payment or some other service, a valid e-m...
  • Critical Out-of-Band Update Released for MS10-046
    Microsoft released Security Bulletin MS10-046 out-of-band to address a vulnerability in Windows. The security update is identified as crit...
  • Adobe Flash Player Critical Security Updates
    Adobe Flash Player was updated to address critical security vulnerabilities.  These updates address a vulnerability that could cause the ap...
  • Hotmail Security to Protect and Recover Your Account
    Time and time again I see reports from Hotmail users who have lost control of their e-mail account.  As explained by Walter Harp, Director o...
  • Long Awaited Outlook.com Calendar Refresh Rollout
    The long-awaited Outlook.com calendar refresh has been released and is in the process of being rolled out. Because the servers are grouped i...
  • Microsoft Security Advisory 2269637 Released
    Microsoft released Security Advisory 2269637 which relates to a remote attack vector to a class of vulnerabilities affecting applications t...
  • Mozilla Firefox 3.6.13 Security and Stability Update
    Mozilla Firefox 3.6.13 has been released to fix stability issues and address the following security vulnerabilities: MFSA 2010-84 XSS h...
  • Adobe Reader Security Updates
    Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.03) and earlier versions for Windows and Macintosh. Adobe identif...
  • Advance Notice: Security Updates for Java SE
    The Sun Security Blog published the following update announcement: "On November 3, 2009, Sun will release the following security update...
  • Adobe Flash Player and Adobe Air Security Updates
    Adobe released updates to both Adobe Flash Player and Adobe AIR to correct a critical vulnerability in both products. From the Adobe Securi...

Categories

  • Adobe
  • Advisory
  • Amero
  • AntiVirus
  • Apple
  • Ask
  • AVG
  • Bing
  • Browser
  • Child Safety
  • email
  • ESET
  • Ethics
  • Facebook
  • Firefox
  • Firewall
  • FixIt
  • Fraud
  • General
  • Google
  • Hotmail
  • IE10
  • IE6
  • IE7
  • IE8
  • IE9
  • Java
  • Lavasoft
  • malware
  • Microsoft
  • Microsoft Apps
  • Mozilla
  • MVP
  • NCSAM
  • Office
  • Office 2007
  • Office 2010
  • Opera
  • Outlook.com
  • Phishing
  • Privacy
  • safety
  • Search
  • Security
  • Service Pack
  • SkyDrive
  • Skype
  • Software
  • SP1
  • sp2
  • SP3
  • Spotlight
  • Sumatra
  • tutorial
  • UAC
  • Updates
  • Vulnerabilities
  • Windows
  • Windows 7
  • Windows 8
  • Windows Live
  • Windows Live OneCare
  • Windows Vista
  • Windows XP
  • WinPatrol

Blog Archive

  • ▼  2013 (93)
    • ►  October (2)
    • ►  September (8)
    • ▼  August (9)
      • Microsoft Account Aliases and Primary Email Account
      • Managing Formerly Linked Microsoft Accounts
      • Firefox 23.0.1 Released
      • Microsoft Security Updates for August, 2013
      • WinPatrol 28.6.2013 Released
      • Security Bulletin Advance Notice for August, 2013
      • The Danger of Saved Browser Passwords
      • Mozillia Firefox 23.0 Released with Critical Secur...
      • Update! WinPatrol Friends and Family Special Discount
    • ►  July (5)
    • ►  June (8)
    • ►  May (7)
    • ►  April (15)
    • ►  March (9)
    • ►  February (16)
    • ►  January (14)
  • ►  2012 (98)
    • ►  December (7)
    • ►  November (6)
    • ►  October (11)
    • ►  September (5)
    • ►  August (10)
    • ►  July (8)
    • ►  June (12)
    • ►  May (7)
    • ►  April (12)
    • ►  March (6)
    • ►  February (6)
    • ►  January (8)
  • ►  2011 (130)
    • ►  December (8)
    • ►  November (10)
    • ►  October (7)
    • ►  September (12)
    • ►  August (9)
    • ►  July (6)
    • ►  June (13)
    • ►  May (14)
    • ►  April (13)
    • ►  March (15)
    • ►  February (10)
    • ►  January (13)
  • ►  2010 (146)
    • ►  December (10)
    • ►  November (15)
    • ►  October (19)
    • ►  September (15)
    • ►  August (14)
    • ►  July (8)
    • ►  June (19)
    • ►  May (5)
    • ►  April (11)
    • ►  March (6)
    • ►  February (14)
    • ►  January (10)
  • ►  2009 (33)
    • ►  December (11)
    • ►  November (11)
    • ►  October (11)
Powered by Blogger.

About Me

Unknown
View my complete profile