Chrome and Firefox password storage methods are said to have security risks

by anonymous on 2013-08-12 21:47:36

Firefox

English Original: Chrome, Firefox store saved passwords in plain text

If someone has physical access to a machine, it is relatively easy for them to discover the plain-text passwords stored by Chrome and Firefox.

In the Chrome browser, entering "chrome://settings/passwords" will display a list of saved passwords. By selecting one and clicking "show password," the plain-text password can be revealed. In Firefox, go to the menu and select "Options" -> "Options" -> "Security" -> "Saved Passwords" -> "Show Passwords," which will display all saved passwords in plain text. However, Firefox also provides users with a "Master Password" option to encrypt the saved passwords. Google states in its user agreement that it does not take responsibility if saved passwords are stolen. It explains that disabling the "Show Password" feature would only provide a false sense of security because, if someone has physical access to the machine, anyone can view locally stored passwords by browsing the hard drive or running a JS program.