Home Reviews About
Twenty of Time

Treat Browser-Saved Passwords Like Plaintext

A browser password manager is convenient because it removes friction from everyday logins. Open Chrome, Firefox, Safari or Edge, visit a familiar site, and your credentials may appear automatically. That convenience can make saved passwords feel as safe as those stored in a dedicated password manager. The underlying protection is usually more conditional than people realise.

The important distinction is between encryption at rest and practical secrecy. A browser may encrypt its password database, but the browser, operating system account, synchronisation service and unlocked device may all have access to the key. If an attacker controls your session or steals your browser profile, the encryption may offer little protection.

Treating saved passwords like plaintext does not mean throwing away every browser feature. It means adopting a cautious mental model: assume that anyone who gains meaningful access to your computer, browser account or device could eventually obtain the credentials stored there. That assumption leads to stronger passwords, better compartmentalisation and less dangerous reuse.

What the browser is actually protecting

Browser password stores are generally kept in an encrypted database. On a modern laptop, the encryption key may be protected by the operating system’s credential store, such as Windows Credential Manager, macOS Keychain or a Linux secret service. This is a valuable barrier against someone casually copying a profile directory from a powered-off machine.

The barrier becomes weaker after you sign in. Once the operating system has unlocked your session, the browser needs to retrieve credentials for autofill or display them when requested. Malware running under your account may be able to interact with the browser, inspect its memory, abuse accessibility features or query the local password store. An attacker does not always need to break the database mathematically.

The same principle applies to browser synchronisation. Sync can protect data while it travels between devices, but a compromised Google, Microsoft, Apple or Mozilla account can expose a large collection of passwords at once. A stolen session cookie, recovery email or weak account password may provide a route around the safeguards you expected to protect the vault.

This is why “encrypted” should not be treated as a synonym for “inaccessible”. It describes a technical layer, not a guarantee that credentials remain secret after endpoint compromise. The browser is part of the attack surface, and the account that unlocks the browser may be an even more attractive target.

A logged-in computer is a useful target

Physical access changes the risk substantially. A housemate, colleague, repair technician or thief who obtains an unlocked laptop may be able to open password settings, trigger autofill, copy browser data or add a malicious extension. Even a short absence at a coworking space in Melbourne can create more exposure than users expect.

Device encryption helps when a laptop is shut down and stolen. It does little if the computer is awake, logged in and already trusted. Automatic screen locking, a strong device passcode and separate operating system accounts are basic protections because they reduce the period in which someone can use the browser as its owner.

Malware is the more serious version of the same problem. Infostealers are built to search for browser databases, cookies, session tokens, cryptocurrency wallets and saved payment information. They may arrive through cracked software, fake updates, malicious advertising or an attachment that looks relevant to work. A password manager inside the browser is valuable data to software designed specifically to harvest it.

Browser extensions deserve particular scrutiny. An extension with broad permissions may read pages, modify content or observe information entered into forms. Some extensions are acquired by new owners, compromised through their development pipeline or quietly changed after building a large user base. A cautious review of extensions, including a browser privacy review, is more useful than assuming a well-known browser makes every add-on trustworthy.

Autofill can expose more than passwords

Saved login credentials are not the only information at risk. Browsers may remember addresses, phone numbers, identity details and card information. Autofill features can place that data into fields that users did not intend to complete, especially on poorly designed or malicious pages.

A deceptive website may copy the appearance of an Australian bank, parcel company or government service. The address bar can be manipulated visually, and a page can contain hidden or misleading form fields. If the browser decides that a page resembles a saved login, it may fill fields before the user has carefully checked the domain. Password managers that require an explicit action to fill are generally safer than completely automatic behaviour.

Phishing does not always need the password itself. A stolen session cookie can sometimes let an attacker bypass the login screen and a second factor. This is especially damaging for email, social media and cloud accounts, because control of one account can enable password resets for many others.

Australian users encounter convincing scams around myGov, Medicare, Australia Post, toll notices and major banks. Scam messages often create urgency, using an unpaid invoice or account suspension to push people towards a lookalike page. Saved credentials increase the consequences of clicking because the browser may make a fraudulent login feel routine. Check the domain independently, use a bookmark for important services and avoid logging in from links in unexpected messages.

Reuse turns one leak into many

The greatest danger is often password reuse rather than the browser database itself. If the same password protects an email account, an online retailer and an Australian banking service, a breach at the retailer can become a compromise of the other accounts. Attackers automate this process with credential-stuffing tools that test leaked username and password combinations across popular websites.

Password reuse is common because people are managing dozens of accounts. An Australian household might use logins for a bank, energy provider, supermarket loyalty scheme, streaming service, school portal, work platform and government account. Saving all of them in one browser profile creates a convenient catalogue for an attacker, while reusing a short password makes every entry more valuable.

Unique passwords limit the blast radius. The most important accounts should have separate, long credentials: primary email, password manager, banking, cloud storage, identity services and work accounts. Randomly generated passwords are preferable because human-created variations tend to follow predictable patterns, such as adding a year or changing a final exclamation mark.

A breach notification should trigger immediate action rather than resignation. Change the exposed password on the affected service, change it anywhere else it was reused, revoke active sessions and inspect recovery details. If the affected account is connected to payments or identity documents, contact the provider through an independently verified channel.

Better protection than a single browser vault

A dedicated password manager can provide stronger separation than a browser profile. Its master password protects a vault designed specifically for credential storage, and reputable products often support secure sharing, breach alerts, multi-device access and clearer controls over autofill. The software still runs on an endpoint, so it cannot make an infected computer safe, but it can reduce casual exposure and encourage unique credentials.

Passkeys offer another useful direction. They use cryptographic key pairs rather than a reusable secret that can be typed into a phishing page. The private key remains on a device or security key, while the service stores a public key. Passkeys are not a universal replacement yet, but they can remove many password theft and reuse problems where services support them.

Multi-factor authentication remains essential for accounts that still use passwords. An authenticator app or hardware security key is generally stronger than SMS, although any second factor is better than a password alone when the alternatives are limited. For high-value accounts, security keys provide strong resistance to common phishing attacks.

A sensible arrangement might use a dedicated manager for most credentials, passkeys where available, and the browser only for low-risk accounts or temporary convenience. Some people may prefer a local vault rather than cloud synchronisation; others may value encrypted sync for reliability and recovery. The key question is where the master key lives, what protects it and how quickly access can be revoked after a lost device.

For people who spend much of their day online, reducing tracking also matters. Advertising networks and compromised pages can increase exposure to malicious scripts and deceptive content, so a considered ad blocker review can help explain the trade-offs between blocking, site compatibility and privacy. Blocking advertisements is not a substitute for password security, but it can remove some routes through which harmful content reaches the browser.

A practical password routine

Start by protecting the email account that controls password resets. Give it a unique generated password, enable multi-factor authentication and review signed-in devices and recovery addresses. If an attacker controls email, they may be able to take over every other account even when those accounts use different passwords.

Next, inventory the browser vault. Most browsers can show saved credentials, alert you to known compromised passwords and identify reuse. Do not export the complete password database to an unencrypted spreadsheet. Replace the most sensitive entries first, then move the remainder into a password manager or convert them to passkeys where possible.

Review the devices that access the vault. Remove old laptops, phones and tablets, install operating system updates, enable full-disk encryption and set short automatic screen-lock periods. On a shared family computer, use separate accounts rather than relying on different browser windows. At work, follow the organisation’s security policy and avoid storing business passwords in a personal profile.

Privacy is a broader habit than a single setting. The essays and commentary collected at Twenty of Time explore how surveillance, data collection and technology policy shape ordinary digital decisions. That wider context matters because credentials are valuable precisely when they can be linked with browsing history, contact details, location and purchasing behaviour.

The goal is not to panic about every saved login. It is to recognise that a browser is an active application with access to valuable secrets, running on a device that may eventually be lost, infected or misused. Keep the convenience for low-consequence accounts, reserve your strongest protections for identity and financial services, use unique passwords or passkeys, and lock the device whenever you step away.