Jump to content

Passwords saved in Chrome are synced to your Google Account in Plaintext


Batu69

Recommended Posts

Don’t use Chrome’s built in Password manager, it syncs to your Google Account where passwords are viewable in plaintext. Have you ever saved a password in Chrome, even accidentally? Go to passwords.google.com

1*JC3IzQAcpt8BvFNntRewOg.png

All the passwords you’ve ever saved

Ever given your Google password because you couldn’t access your email? They can wire your savings to themselves.

Just got out of a serious relationship? Your ex-girlfriend probably piggybacks off your Netflix subscription.

Why is this a problem?

  • I’ve seen a real world case where a Google account compromise led to a takeover of social media accounts unrelated to the address.. this was the only place where the passwords were stored
  • This defeats resetting the victim’s password to gain entry into their accounts, and allows for “silent” stalking after obtaining the Google password.

How do I protect myself?

Read my guide, and use LastPass:

Disclosure:

  • May 18: Contacted Google and proposed short-term solutions
  • May 18: Google riaged and put into queue
  • May 24: Not considered a security bug.. oh well.

Article source

Link to comment
Share on other sites


  • Replies 13
  • Views 782
  • Created
  • Last Reply

 :eek: Luckily I'm a LastPass and StickyPass user.

Link to comment
Share on other sites


Best password manager is only your brain . ;)
I do not trust all of these crap called " Password Managers ".....:fist:

Link to comment
Share on other sites


2 minutes ago, Recruit said:

Best password manager is only your brain . ;)
I do not trust all of these crap called " Password Managers ".....:fist:

Certainly, I never save highly confidential passwords such as online banking password in browser or password manager. All passwords are in my mind. 

Link to comment
Share on other sites


  • Administrator

Talking about passwords, it's always important to never save really important financial related passwords anywhere, including password managers and browsers - always retype your really important passwords. For the rest password managers are good, but make sure your important passwords and non-important passwords are completely different I think.

Link to comment
Share on other sites


Misaki2010

LastPass user here :D I never trust browsers to remember my passwords :)

Link to comment
Share on other sites


5 hours ago, Recruit said:

Best password manager is only your brain . ;)

  1. Which is the latest version?
  2. Download link, please.
Link to comment
Share on other sites


12 hours ago, dcs18 said:
  1. Which is the latest version?
  2. Download link, please.

 

  • It doesn't matter the version, but one thing's sure : as days go by it is a downgrade considering that we are losing neurons...:P
  • The link is located into fanclub`s intranet. Connoisseurs know why...<_<
Link to comment
Share on other sites


20 hours ago, Recruit said:

Best password manager is only your brain . ;)
I do not trust all of these crap called " Password Managers ".....:fist:

The human brain can't remember 100's of unique passwords. I save all my account passwords in a password protected Excel spreadsheet and never had a problem. You should never use the same password anywhere twice, change banking/financial passwords every 3 months. Don't use words for passwords, use a random password generator make the password as long as possible. Also, you should be more worried about your passwords being leaked or lost by some dumbass executive at your local bank who lost his laptop with no data encryption at all.

 

A password of K'Q+vC"U)h{.7Ku} vs nsane12345 is going to be much harder to hack.  Enter your email address here to see if one of your accounts was stolen/leaked.

 

Change Your Passwords: 560 Million Email Credentials Have Been Leaked 

http://lifehacker.com/change-your-passwords-right-now-560-million-email-cred-1795291120

 

 

Link to comment
Share on other sites


Akaneharuka
16 hours ago, dcs18 said:
  1. Which is the latest version?
  2. Download link, please.

 

lol I laugh around  2 min because of this. . . . 

Link to comment
Share on other sites


Google saved passwords are encrypted even on your computer and also encrypted on the web.

If You are the owner and logged in, of course then they must be decrypted, to see them. Not needed talk that they are not encrypted on the web.

It's only weird LastPass advertising here.

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...