Browser password managers – flawed security, by design
fractionalciso.com
Browser password managers – flawed security, by design
1–10 of 127 posts
Re: Browser password managers – flawed security, by design
#2Re: Browser password managers – flawed security, by design
#3And if the organization in question isn't using Bitlocker or FileVault or some other encryption, browser password stores are way down the list of security worries.
Re: Browser password managers – flawed security, by design
#4If they have that access you have bigger problems on your hand. Yes, this can lead to privilege escalation, but for the vast majority of people access to the desktop is enough for that anyway.
If you need better security, you probably already are using more advanced measures.
Re: Browser password managers – flawed security, by design
#5> then your average employee is probably doing one of these three things: Writing passwords down on paper
> Hopefully, you have a corporate security awareness training program and have long been discouraging
Please, please encourage people to write down passwords on paper! That provides really good safety against most modern threat models, especially in a world where people are working from home.
> Even though Chrome, Firefox, and Edge browsers all store passwords in encrypted databases, by default all three products intentionally leave the associated encryption keys completely unprotected in predictable locations.
There was (is?) a long lived Chrome issue (which I can't find now). They reasonably make the point that operating system level protection is the correct way to protect this (ie, if a person can log onto your device they are assumed to be you).
Re: Browser password managers – flawed security, by design
#6Re: Browser password managers – flawed security, by design
#7If you are a business and you want your employees to be secure, forget about anything to do with passwords. You need hardware second factor tokens. Which I notice the article doesn't mention at all. An article about login security in 2022 that doesn't even mention hardware tokens for two factor authentication is not worth anyone's time.
Re: Browser password managers – flawed security, by design
#8Re: Browser password managers – flawed security, by design
#9Is this a laptop without disk encryption that travels a lot and especially internationally? Sure, these semi-unencrypted passwords on disk are likely not very safe from lost laptops, customs inspections, etc. Might still be better than a common and simple password though.
Is this a laptop sitting at home most of the time with a strong disk encryption? I’ll take unsecured browser password storage with unique hard passwords any day.
Edit: formatting
Re: Browser password managers – flawed security, by design
#10Keen to understand the hackernews take on this...