Using Google Chrome to manage your passwords is a bad idea. Here’s why.

What do privacy experts say about using Google Chrome and other browsers for password management? Neil J. Reuben King(opens in new tab) Mashable’s sibling site PCMag has the answer.

password manager(opens in new tab) It’s been around since the 90’s and the major browsers are(opens in new tab) Password management was added as a built-in feature in the early 2000s. Since then, PCMag has recommended getting passwords out of insecure browser storage and into a good, well-protected password manager. Back then, you could point to a password manager that would extract passwords from your browser, delete them from your browser, and turn off browser-based password capture. It’s certainly not safe!

Related item:

The best password manager for all your online accounts

Thankfully, browsers have come a long way and passwords are no longer exposed to outside manipulation.If you want to switch to a dedicated password manager(opens in new tab)For example, passwords might need to be actively exported from browsers and imported into new products.

But are browsers advanced enough to recommend storing passwords in the browser? Specifically, should you use the Google Password Manager conveniently built into Chrome? , the answer is overwhelmingly no.

Even Dedicated Password Managers Can Be Leaked

For a password management-based enterprise, trust is everything. Serious competitors use zero-knowledge techniques to protect your encrypted data so that no one, password companies, governments, can learn your master password.(opens in new tab) or decrypt the data.

Nevertheless, implementation errors can compromise password security. In a series of revelations that began last August, a hacker compromised the computer of a key LastPass employee.(opens in new tab) Steal an unknown number of encrypted vaults. To make matters worse, some critical data elements, such as login domains, were not encrypted. It’s hard to trust LastPass(opens in new tab) now.

key pass(opens in new tab) is a technician’s favorite password manager due to its endless customization possibilities.But that same customization power is manifested as a sort of Achilles heel.(opens in new tab) Or you can sit in your absence and steal all your Keepass passwords(opens in new tab)Using Notepad, it’s trivial to create an action that exports the password to plain text and sends the resulting data to a drop on the internet. Granted, it might be difficult to get the access you need, but the exploit is possible (opens in new window)(opens in new tab). Or rather, was Possible. His latest KeePass update 2.53.1 removed the option to export passwords without requiring the master password to be entered.

How to enable or disable Google Password Manager

Before we tell you if you should use Google Password Manager, let’s see how to shut it down (or wake it up if you want). First, make sure sync is enabled on all Chrome instances that share passwords. Click the three-dot menu in the top right corner of the Chrome window,[設定]Click. The top item in the left rail menu titled You and Google should be selected first. If not, click. In the dialog that appears, you can toggle syncing on or off.

How to change password settings in Google Password Manager


Credit: Google

Click Autofill just below You and Google, then click Password manager. If you use Google Password Manager,[パスワードの保存を提供する]and[自動サインイン]item. If not, turn them off.

Learn more about how to master Google Password Manager.(opens in new tab)No, we do not recommend it for security reasons. But yes, we know some people are willing to sacrifice safety for convenience.

Expert opinion on browser password managers

To supplement my own knowledge and experience, I called experts from several well-known commercial password manager companies, including Keeper co-founder and CTO Craig Lurey.(opens in new tab); node path(opens in new tab) CTO Thomas Smarakis; Bitwarden CEO Michael Crandell(opens in new tab).

Browser password managers are useful but dangerous

Smalakys led the warning against the use of browser password managers, stating, “Despite cybersecurity experts’ continued warnings about vulnerabilities in browser password managers, Internet users still say, ‘But it’s convenient. A trap.” Lurey agreed, pointing to a recent Keeper blog post(Opens in a new window).(opens in new tab) We’ve gone through a long list of reasons why browser password managers are insecure.

Zero-knowledge encryption is why a dedicated password manager can keep your data safe without access to your master password. “Google’s password manager does not use zero-knowledge encryption,” Lurey said. “Basically, Google can see everything you store. keys are stored on the device. ”

Smalakys agreed that data stored in browsers is not protected like data in password managers. “Hackers use social engineering techniques to trick internet users into downloading new extensions that can easily extract data stored in their browsers,” he said. He continued: Therefore, Internet users should choose a service his provider that guarantees end-to-end encryption. ”

Crandell gutted Google by saying, “Any password manager is better than no password manager.” If you need to operate in a different browser, or in an environment that that browser doesn’t reach, you’re out of luck. ”

Password manager has more features

Lurey provided a list of simple ways Chrome’s built-in password manager fails to meet the standards of a dedicated password manager program. First, this is Chrome specific. If you’re using a different browser, you’re up a clique.No option to securely share passwords, no option to establish digital heirs(opens in new tab) For password collection. Your browser only stores your passwords, not your personal information such as your address, account number, or credit card.

Crandell also emphasized that browser-based password systems lack important features. He said such systems would include “secure sharing of passwords with colleagues and family, support for biometric logins and security keys, reports on whether passwords are weak, reused or compromised; It lacks integration with workplace systems such as SSO, and many other features.” feature. ”

Smalakys said: “Most browsers don’t require a master password or multi-factor authentication (MFA)(opens in new tab) Approved. “Google allows MFA, but it’s not required. In fact, there is no master password. If you leave your desk with Chrome active, anyone with access can log in to your account. Others The same is true if you let someone use your phone.

your browser locks you in

“Be careful not to lock yourself in the walled garden of a large corporation,” warned Crandell. “It’s important to have the freedom to work across all platforms and environments: browser, mobile, and desktop operating systems.”

Smalakis pointed out the dangers of connected accounts. “In one scenario… when using the Chrome browser, its safety depends on how secure his connected Gmail account is,” he said. “If this Gmail account is compromised, a hacker can easily access the passwords of all other accounts stored in the browser.” Similarly, Lurey said, “Users should protect their information. You have to trust Google completely to do it.” If your Google account is compromised, so are all your passwords.

Browsers are designed for browsing. Password management is an afterthought. “Dedicated password managers are committed to developing secure and independently audited password managers to ensure security,” he concluded Smalakys. Crandell echoed a similar opinion, stating, “The leading password manager is more capable because he’s 100% focused on achieving both optimal security and his case of many uses of passwords.” abundant.”

In short, get a real password manager

Google Password Manager does not use zero-knowledge encryption technology to protect your password data from anyone, including the password manager company. I don’t even use a master password. Dedicated password tools offer many features you can’t get with the built-in browser. Also, Google’s password system is only available for Chrome (or Android to some extent). These are just some of the reasons why you should get a real password manager instead of relying on Chrome.

Having Google Password Manager come as a free feature in a free browser is very convenient. However, this is not a good reason to accept that password security is limited.I’ve rated many free password managers(opens in new tab) Great protection for your passwords for the same $0 price. Use one of them instead.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *