Never Store Passwords in a Web Browser - Here's Why

Поділитися
Вставка
  • Опубліковано 3 жов 2024

КОМЕНТАРІ • 253

  • @minhajsixbyte
    @minhajsixbyte 3 роки тому +186

    Limitations: Attacker must have full access 1:20
    Dude! If attacker already has full access then you are already .....

    • @erce1000
      @erce1000 3 роки тому +17

      I agree with that. If they have access of course they could do mostly anything

    • @collinsinfosec
      @collinsinfosec  3 роки тому +30

      It's about limiting the attack surface. If an attacker were to get access to your device, they could encrypt your files - I would agree. But they could also get your passwords as well - if stored in a browser.

    • @lokeshkoliparthi9268
      @lokeshkoliparthi9268 3 роки тому +35

      @@collinsinfosec if attacker can get physical access or fully remote access(can control input/output) to computer then they could just export passwords to a file without need of any kind of scripts.

    • @TimeoutMegagameplays
      @TimeoutMegagameplays 3 роки тому +11

      @@lokeshkoliparthi9268 If you are using a password manager the hacker would still have to keylog you master password, and would need access to your 2FA (which I really hope you are using), so the passwords are still safe.

    • @nishantgupta1854
      @nishantgupta1854 3 роки тому

      wow haha

  • @siriusleto3758
    @siriusleto3758 3 роки тому +51

    Keyloggers. Never type on your keyboard, here's why. Limitation: Physical access.
    Spyware. Never speak into your microphone, here's why. Limitation: Physical access.
    Spyware. Never use the monitor to view your data, here's why. Limitation: Physical access.

  • @An1m3
    @An1m3 3 роки тому +248

    Good thing I have my passwords on a word document.

    • @pixums
      @pixums 3 роки тому +20

      even worse..

    • @rakeshchowdhury202
      @rakeshchowdhury202 3 роки тому +3

      If it's inside a veracrypt vault

    • @siriusleto3758
      @siriusleto3758 3 роки тому +2

      Bad ideia. If you have been infected you cannot escape. It is even easier to read a word document, as you don't need to decrypt it, you don't need to use specific software.

    • @siriusleto3758
      @siriusleto3758 3 роки тому +9

      @EnergySandwich Maybe. I've met someone who backed up the file in the Windows recycle bin.

    • @calebpersonal9987
      @calebpersonal9987 3 роки тому

      All fun and games till you get ratted and someone downloads that file

  • @aaaaaa8711
    @aaaaaa8711 3 роки тому +251

    if someone has access to the device its already compromised or encrypt your device. this video is kind of misleading.

    • @erce1000
      @erce1000 3 роки тому +7

      I agree

    • @rahuldora1587
      @rahuldora1587 3 роки тому +2

      Yeah you are right.

    • @adityaj7664
      @adityaj7664 3 роки тому +2

      Yeah!

    • @alvinxyz7419
      @alvinxyz7419 3 роки тому

      clickbait right

    • @TimeoutMegagameplays
      @TimeoutMegagameplays 3 роки тому +11

      Still, if he's using a password manager and notices that the machine has been for instance backdoored, he can simply format completely and reinstall the system, as long as he doesn't access his passwords from his password manager it's still safe, so it's still better than having it on the browser.

  • @SweDownhill
    @SweDownhill Рік тому +28

    If you are afraid of using password managers.. consider using them but store partial passwords. What I mean by that is that you simply add or subtract a special sauce that only you know about. By doing so, credentials stored in a password manager will never be sufficient to login so they become useless for everyone else that might get a hold of them.

    • @fearless6947
      @fearless6947 Рік тому

      What Swedownhill means is, save the password that google password manager gives you (SAVE it). An example could be on your amazon account. Recreate a new password on your amazon account but, this time, use the same password and add words or letters to the password (this time do NOT save it in google password manager). Everytime you log in, just add an extra word to it.

    • @SweDownhill
      @SweDownhill Рік тому +7

      @@fearless6947 Actually no, that's not what I meant. Here's a better example:
      Lets say you generate a password of abc123def456, where/how it was generated doesn't really matter. You can then choose to store that exact password in a password manager. If the vault were to be compromised then the hacker would have access to that password/service. However, if you generate the above password, store it in the vault and then add your own special sauce outside of the vault. Then you, and only you would have access to the actual password. To further elaborate on this idea, let's create a few examples:
      Generated password stored in vault: abc123def456
      Always subtract 2 letters: abc123def4
      Always add QZ to every password: abc123def456QZ
      Etc.
      If you generate another password: qwerty987, then the same logic would be to store that in the vault, and then the actual password would be either qwerty9 or qwerty987QZ depending on the special sauce that was chosen. Of course, you should come up with your own system. These are just for demo purposes.

    • @4lpina
      @4lpina Рік тому +1

      I am not sure how much this would help. If you are using the same system for all your passwords (otherwise what's the point), at some point some crappy website leaks your password and hackers can see your 'sauce' you used for all your password. Essentially you can never really trust this 'sauce' since chances it will leak at some point if you use it for many websites.

    • @charliee5970
      @charliee5970 9 місяців тому +2

      @@SweDownhillNever thought of that, that's good!

    • @charliee5970
      @charliee5970 9 місяців тому

      @@4lpina His idea isn't addressing your situation you gave. In your example literally nothing would help protect your password.

  • @Kyllleur
    @Kyllleur 3 роки тому +56

    On firefox, if you have remote or physical access to the machine, you can just go in the security settings to check the saved usernames and passwords... no need to use any script for that lol (dunno about chrome)
    Honestly, if you got someone with ill intention having access to your PC, you're fucked and that's it.

    • @BobbyPhoenix
      @BobbyPhoenix 3 роки тому +11

      Exactly this. At least he started the video by saying you need 100% full control of the computer. Well yeah if you have that you can do much more stuff than just steal passwords for my browser. That's like saying don't leave your wallet on your kitchen table as you should lock it in the safe behind a picture in the wall, but that's because if someone ever gets 100% full access to your house either by key or breaking in they can steal all your information you have in your wallet. No duh.

    • @afisap6969
      @afisap6969 3 роки тому +6

      But, in firefox you can create master password to prevent it

    • @siriusleto3758
      @siriusleto3758 3 роки тому

      Chrome too. Just use the same Windows password you used when physically hacking your computer and ready, all browser passwords will be shown.

    • @soltanayarix428
      @soltanayarix428 2 роки тому +1

      but bro, python script and linux tools works automaticly and easy

    • @estebanod
      @estebanod Рік тому +1

      On chrome you need to use the pc password to access the passwords

  • @the-mi8hy
    @the-mi8hy 3 роки тому +32

    i audibly let out a sigh of frustration because i know youre right but im too lazy to put effort into remembering my passwords >:(

    • @collinsinfosec
      @collinsinfosec  3 роки тому +7

      Convenience vs Security is always dilemma 😂 Sometimes you have to choose, sometimes you have to meet in the middle.

    • @DiekiKondrael
      @DiekiKondrael 3 роки тому +7

      Remembering your passwords is a worse idea than storing them in the browser. Anyone that can extract passwords from Chrome's storage can also log your keystrokes as you type the password in. Plus, relying on memory to store passwords leads to password reuse, which is a far bigger problem.

    • @092_deepak_kumar3
      @092_deepak_kumar3 3 роки тому +4

      Use Bitwarden

    • @dashy324
      @dashy324 3 роки тому +7

      Use a password manager

    • @ko-Daegu
      @ko-Daegu 3 роки тому +2

      @@dashy324
      Yes + 2FA

  • @asheeeesh27
    @asheeeesh27 3 роки тому +16

    Alternate title: How to get your parent’s Amazon password for Vbux

  • @vickietema3397
    @vickietema3397 3 роки тому +1

    Your content is advanced and refreshing. Very helpful. 👍

  • @billy-cg1qq
    @billy-cg1qq 3 роки тому +68

    Hhhhhh good luck for a hacker to get a full remote control of my laptop

    • @kgaming7599
      @kgaming7599 3 роки тому

      ikr

    • @Nerd2Ninja
      @Nerd2Ninja 3 роки тому

      The laptop would be easier than a desktop to get full remote access to assuming you ever connect it to wifi

    • @Hello_am_Mr_Jello
      @Hello_am_Mr_Jello 3 роки тому

      hhhh dahka mrokia

    • @tyrellwreleck4226
      @tyrellwreleck4226 3 роки тому

      Even modern routers have firewall protection against modern attacks.

    • @Synceditxboxoffice
      @Synceditxboxoffice 3 роки тому

      if you are connected to internet via Ethernet or WiFi doesn't matter that cause someone will connect to the network or more likely hacker will connect to your router and then hack all the devices connected to that particular router he will poison it and boom he will have all the thingssss lolx

  • @amarat.
    @amarat. 3 роки тому +7

    It’s kinda hard to get direct access to a Linux machine these days lol. Also, half of these vulnerabilities have been patched, and continue to get patched.

  • @farfromwea.k
    @farfromwea.k 3 роки тому +2

    If i have someone else windows password, i will simply open chrome, head to password and browser will ask the windows password again and will simply put it there as well and see/copy password. Using browsers to save password is not insecure but you have to be secure enough not to have anything let your pc or browser access it.

    • @faithfulojebiyi
      @faithfulojebiyi 3 роки тому

      It's just the same as someone having the password to your password manger fam

  • @vladgonzaleza8774
    @vladgonzaleza8774 3 роки тому +4

    This makes no sense. Attackers can also end emails from your account and gain access to your bank account... if they have access to your account.

  • @Rhidayah
    @Rhidayah 3 роки тому +1

    I don't know why, you just suggesting to use password manager. As mention kevin mitnick or edward snowden, I forgot who say that "you don't use password manager" its just pushed you to out from scure password and just collecting your password to be generic password

  • @johnczech7074
    @johnczech7074 3 роки тому +4

    Grant thank you. Your content is always excellent!!

  • @WantBadtime
    @WantBadtime 2 роки тому +1

    I learned it from the hard way. My accounts linked through google Password manager, including my Google account, got compromised by a phishing auto token grabber. I am also learning Security Awareness and all browsers create a specific encrypted file with ALL passwords with jumbled text. With that file, they can use a cracker to get every single email and password in just a click. It is absolutely unacceptable. You are best just making your own strong password and write it in a small journal/composition book.

  • @stevejobzz7756
    @stevejobzz7756 3 роки тому +17

    Time to time chrome has fixed the patch effectively , no need to worry about security issue its just info video

  • @tentrot4420
    @tentrot4420 3 роки тому +8

    I know I asked this question before but do you know anything about cryptography? Just curious

    • @collinsinfosec
      @collinsinfosec  3 роки тому +1

      I do know the basics of cryptography, but I am not well-versed in the area of how the algorithm actually works or was developed from the mathematical perspective (math probability, etc).

  • @aland9328
    @aland9328 3 роки тому

    Use password managers! I recommend bitwarden

  • @johnswanson217
    @johnswanson217 3 роки тому +8

    1. Close your remote access if not necessary.
    2. Do not use unsafe public networks if your machine is remotely accessable.

  • @DogsAreGods
    @DogsAreGods 10 місяців тому +1

    So, in conclusion, really, saving your passwords in your browser is fine just as long as you keep everything updated, and you keep your network and home OS secure from RATs exploiting backdoors.

  • @nexusjump
    @nexusjump 3 роки тому +7

    Cool..Thats a great tip
    Thanks man😅😅

  • @Medienmechaniker
    @Medienmechaniker 3 роки тому +8

    currently using bitwarden with the chrome extension. Is the extension okay to use security wise?

    • @erce1000
      @erce1000 3 роки тому +1

      Yeah, good question.

    • @collinsinfosec
      @collinsinfosec  3 роки тому

      Good question. I haven't personally used BitWarden. I would say yes. Best possible solution would probably be a local password management such as KeePass.

    • @kareemschultz
      @kareemschultz 3 роки тому

      @@collinsinfosec Bitwarden also has a self hosted version and its code is visible for everyone to see and inspect as oppose to some other password mangers

  • @durzua07
    @durzua07 3 роки тому +12

    I have done this on the past :(

  • @albertobarbieri8280
    @albertobarbieri8280 2 роки тому +4

    Saying that it is easy to steal passwords from the browser is wrong in my opinion. I mean, probably the browser is not the best place, but it's not even the worst place. At the same time it's not that easy to have access to another person's computer in a real world scenario.

  • @holidayseason1205
    @holidayseason1205 2 роки тому

    Hi grant can you make a video on programming in security and if OOP is needed for security

  • @ishantram6956
    @ishantram6956 2 роки тому +1

    After some here and there I am able to decrypt the password saved by chrome which is above chrome version 80.

  • @edwardmacnab354
    @edwardmacnab354 2 роки тому +1

    How are they going to get access to my machine. Also all my passwords are linked to a G-mail account that has a backup account in my service provider and also a phone contact so finding my password to IG or Tik Tok would be pretty temporary. I am a bit worried about when I do sign up for online banking as I don't believe banks are that bright generally and I'm a bit leary of PayPal too although they may be smarter than the bank in matters of IT and Security.

  • @roffe2k736
    @roffe2k736 3 роки тому +11

    I'm from the future, I've already seen the whole video.

    • @tentrot4420
      @tentrot4420 3 роки тому +3

      What is going to be the next vid? 😂

    • @roffe2k736
      @roffe2k736 3 роки тому +6

      Okay... just so you know you can't tell this to anybody, the next video is going to be a crash course about the bash terminal and permissions in Linux for cybersecurity reasons.

    • @htetaunglwin8941
      @htetaunglwin8941 3 роки тому

      Incredible,I don't believe.

    • @collinsinfosec
      @collinsinfosec  3 роки тому +2

      Can you guess what I am thinking... 🤔 (**cough dee boo dah **cough).

    • @roffe2k736
      @roffe2k736 3 роки тому +1

      ​@@collinsinfosec Exactly! You got one secret, your biggest goal that you want to accomplish is making the "dee boo dah" virus go viral and take over the world with the new ransomware technology you're secretly working on. Sorry, but you asked me for this so the world has to know now...

  • @DanielRamirez-wz7gk
    @DanielRamirez-wz7gk 3 роки тому +2

    You kinda remind me of Eddie Brock Jr. In Spider-Man 3 (2007)

  • @theghostly36
    @theghostly36 2 роки тому

    U should save ur passwords in lastpass its the best

  • @Andoresu96
    @Andoresu96 3 роки тому +1

    Dude if someone already has remote code execution you lost. This is kinda fumb, like even if you encrypt your passwords, you have to type your master password to decrypt, which if you system is compromised to this level, you lost as well.

  • @teamhairball4182
    @teamhairball4182 2 роки тому +2

    Is it the same problem if you use your password manager as an extension in your browser? That seems to be the only solution for autofill, but I always wonder if it leaves your data clear out in the open after you've unlocked it.

    • @Euronius
      @Euronius Рік тому

      Apparently if you store your passwords with Keepass 2, it has an autofill feature where you just tab into Keepas, press Paste (Ctrl + V) and it will autofill the username AND password for you on the webpage. I just found this out today. Might actually use it solely for this one, neat feature.

  • @aakashjana6225
    @aakashjana6225 3 роки тому +5

    Meanwhile my mind thinking how to update the code to work on chrome ver 88

  • @mckinley3
    @mckinley3 3 роки тому

    Great explaining.

  • @KINGABDUL99
    @KINGABDUL99 2 роки тому +1

    Great video Thank you fro telling

  • @ADHD_Gamer
    @ADHD_Gamer 2 місяці тому

    The average person WILL NOT have python installed. And as mentioned in the comments, having full access of target computer is a moot requirement for this test. Target already has issues.!

  • @jackeyniraula
    @jackeyniraula 3 роки тому +1

    lol, this is just a bit overcomplicated process for a simple expected result. If an attacker has full access to the victim's PC, he can get the passwords stored in the browser in less than 5 secs.
    The best advice if you store passwords in the browser is to get the USB security key and enable 2FA requiring security key and store passwords only for the services that have 2FA enabled. Attackers can still have your passwords but can't do shit about it to get access as long as you have the security key. The rest of the passwords should go to your password vault like Keepass. Also, don't trust online password managers, instead use offline password managers like Keepass.

  • @aquatrax123
    @aquatrax123 2 роки тому

    This type of attack can be used on any password manager. The solution here is to have a hardware password manager. There are a few out there but they are not that good for example, Ledger Trezor and Mooltipass Password Managers.

    • @Wan_Destroyer
      @Wan_Destroyer 2 роки тому

      Google Patch this
      (Locked Database)

  • @naingko00
    @naingko00 Рік тому

    Can I save passwords in my Google account only? Not in any browser. I have to save passwords in my Google account only because I can't remember all passwords from all website. Can you give me possible way to solve that problem?

  • @removeall23
    @removeall23 2 роки тому

    Thank you thank you thank you, finally I convence my family to stopped this practice

  • @hypeboy306
    @hypeboy306 Рік тому

    i didn't even stored my passwords in browser but because of malware they take away all login details of the accounts which i logged in the browser like insta,fb,youtube and google account...........even the 2 key factor authentication is on still they hacked my accounts

  • @DiekiKondrael
    @DiekiKondrael 3 роки тому +7

    I disagree with your entire premise, and especially the title. Storing your passwords in the browser is 100x better than trying to remember them, since password reuse is a far worse risk.
    Lastpass or other software that allows you to set a master password may be slightly better, but malicious software can either keylog the master password or just extract it from memory. In short, there is no reliable way to keep passwords secure on an infected machine. You should focus your efforts on preventing infection in the first place.

    • @collinsinfosec
      @collinsinfosec  3 роки тому

      I do understand where you are coming from. But I would have to disagree with this opinion. A password management solution is far better as I suggested at the end of the video. I do agree with your last statement.

  • @novianindy887
    @novianindy887 Рік тому +1

    isnt lazagne and the python blocked by most antivirus nowadays?

  • @gbessone
    @gbessone Рік тому

    Can browser extensions steal saved passwords from the browser?

  • @mohsinfareed1797
    @mohsinfareed1797 3 роки тому

    what is the need for noisy background music?

  • @fuseteam
    @fuseteam 3 роки тому

    fairly certain that's why you set a master password in your browser

  • @bladeeda2736
    @bladeeda2736 3 роки тому

    good thing i save my passwords in youtube comment sections

  • @jujuganz8884
    @jujuganz8884 3 роки тому

    Thank god my password is written in my wallpaper

  • @hagiangtruong4173
    @hagiangtruong4173 2 роки тому

    Bad thing is Lazagne does not work well on Windows

  • @kennnnn
    @kennnnn 3 роки тому

    How safe would saving passwords in a .png file be? Just open it with notepad.

  • @zone47
    @zone47 2 роки тому

    Good info but you could have left all the details out for hackers our there on all the tools to use and process to hack someone's password.

  • @HandsomeManNamedTony
    @HandsomeManNamedTony Рік тому

    From the beginning i always store my passwords in a encrypted usb and the decryptor is sonewhere lol

  • @Shkur777
    @Shkur777 2 роки тому

    What about pass? I mean pass
    the standard unix password manager

  • @blrj
    @blrj 3 роки тому

    How about Lockwise by Firefox?

  • @JustinIkeda
    @JustinIkeda 2 роки тому

    A friend got hacked and the hacker sent me an exe that I foolishly opened. He got all of my chrome passwords. He must have used the project tool described here to get my chrome passwords. I checked for any suspicious incoming established connections and my anti virus/operating system is picking up nothing. Should I still be concerned after changing my passwords? I am using a VPN but I'm not sure if that did anything in this situation.

  • @bread6316
    @bread6316 2 роки тому

    well I wrote a password encoder that encodes a json file into a wav file. All you can hear from it are bunch of beeps with a frequency of 8000 and 9000 Hz. I copied the wav file into all of my devices. Decoding it will be easy but no one could guess that lol.

  • @AidenEllis
    @AidenEllis 3 роки тому

    Glad i have my own software for storing these

  • @StephenYT.
    @StephenYT. 3 роки тому

    and if using 2FA?

  • @sameerdubey740
    @sameerdubey740 3 роки тому

    But is it applied to mobile devices also?

  • @KINGABDUL99
    @KINGABDUL99 2 роки тому +1

    Your Awesome

  • @Lmfaorofl17
    @Lmfaorofl17 3 роки тому +4

    You’re most likely fine to store your password in browsers as long as you don’t install or use software that are dubious. Like come on, the attacker would have to have control over your computer, that’s not easy unless you’re asking for it.

    • @collinsinfosec
      @collinsinfosec  3 роки тому

      Yep that is correct. As hinted at in the limitations section, an attacker would need to have access to your machine. The demos were just a couple examples of how post-exploitation could happen in the real-world scenario

  • @sheez-5486
    @sheez-5486 3 роки тому +3

    Thank you for new virus attack idea, i use python...

    • @Kaos.117
      @Kaos.117 3 роки тому

      You must suck at it to think that this is a new idea XD

    • @sheez-5486
      @sheez-5486 3 роки тому

      @@Kaos.117 i do suck XD, but actually i had a virus idea since i started the Pythin XD, how evil am i...

  • @johnveill113
    @johnveill113 3 роки тому

    How about LastPass?

  • @PrevosHD
    @PrevosHD 3 роки тому

    What about encryption by chrome?

  • @pirbaba755
    @pirbaba755 3 роки тому

    Thanks

  • @dongnez
    @dongnez 3 роки тому

    Did u edit this video in linux?

  • @jishnubiju2118
    @jishnubiju2118 3 роки тому

    Is it safe to save in password managers like bitwarden,dashlane etc

    • @livedreamsg
      @livedreamsg 3 роки тому

      Yes. Bitwarden encrypts end to end.

  • @refugioflores2226
    @refugioflores2226 2 роки тому

    Hey what things can cause someone get access to control ur system ? Someone tried to log into my fb I’m sure they got the password from my pc bit idk how they keep getting access to it

  • @deadlockmusic7685
    @deadlockmusic7685 3 роки тому +2

    Thanks man👍🏻

  • @miguelmorenopastor4697
    @miguelmorenopastor4697 2 роки тому

    If the passwords are encrypted with SSL (now is more common) this will not work :)

  • @GamaPerkasa
    @GamaPerkasa 3 роки тому

    mine saved at keep

  • @michaelnolan1715
    @michaelnolan1715 2 роки тому

    I use bitwarden

  • @unverified-user
    @unverified-user 3 роки тому

    I have passwords in encrypted vault on my phone

  • @YourVision09
    @YourVision09 3 роки тому

    thanks

  • @simplifyrangoli9619
    @simplifyrangoli9619 3 роки тому

    Do not save passwords in Google or any website logins

  • @relaxingrainfall100
    @relaxingrainfall100 3 роки тому

    What if you just put your passwords on paper... 😐

  • @phantom3612
    @phantom3612 3 роки тому +1

    That's way too work for getting pwd. You need to make sure user has Python installed (which is common in programmers computer only) and then you need to run that script. for that u need remote access and that's not a joke. If u get it you basically owns the device. U can even run a ransomware's attack much less a script to get pwd

  • @risithranmira
    @risithranmira 3 роки тому

    USEFUL VIDEO

  • @makali2710
    @makali2710 3 роки тому

    Hey bro i am getting virus attack from last 2 month which is crypto tab browser. This virus destroy my system many of time. Please help me

  • @Sanity1532
    @Sanity1532 3 роки тому +1

    This is amazing! Thank you

  • @alphajoker1659
    @alphajoker1659 3 роки тому

    can fond someone anther pc or laptop browser history

  • @danielbichof828
    @danielbichof828 3 роки тому

    did you reported that as bug bounty to google ?

  • @andretarvok7122
    @andretarvok7122 2 роки тому

    eh, redundant no? i mean if someone has access to your pc can't they just dump cookies and bypass both the password and the 2fa since that cookie session is already authenticated?

  • @AnasQiblawi
    @AnasQiblawi 3 роки тому

    but nobody have python installed

  • @yonderalt2662
    @yonderalt2662 3 роки тому

    Well, where else am I supposed to store them? Other services either are on the cloud which runs in the risk of losing everything if thst service dies or is not free, and paying for the access of your passwords suck. Tell me if there is a better FREE SECURE password manager than Ill chanfe my mind.
    Also, the only way this can happen is if someone stole my device. Thst isnt going to hapoen anytime soon. Even if so, Google has many ways to prevent compramise.

    • @Servidor_Publico_do_Ancapistao
      @Servidor_Publico_do_Ancapistao 3 роки тому

      Pen and Paper

    • @yonderalt2662
      @yonderalt2662 3 роки тому +1

      @@Servidor_Publico_do_Ancapistao Again, not free and worse than a browser insert seeing as I have to find rhe paper (if its burried somewhere) and type it letter by letter cause no automatic insertion and "********" (not everything has Shoe Passseord)

  • @premjithappu837
    @premjithappu837 3 роки тому +1

    Ya i stored password in chrome 🙃

  • @stacklysm
    @stacklysm 3 роки тому

    I thought this would be a password manager ad
    (Edit) Oh

  • @Thunder-dp7du
    @Thunder-dp7du 3 роки тому

    Save in safari then

  • @KINGABDUL99
    @KINGABDUL99 2 роки тому +1

    I love u

  • @kakilancap
    @kakilancap 3 роки тому

    Even in your own pc?

    • @collinsinfosec
      @collinsinfosec  3 роки тому

      If you want "optimal" security - I would say yes, even on a personal PC.

  • @rangermark12
    @rangermark12 3 роки тому

    well i already never clicked the button cuz i have a other password manger

  • @WilcoVerhoef
    @WilcoVerhoef 3 роки тому

    You can set a masterpassword in Firefox to prevent this. But at that point why not just install a proper password manager

  • @KINGABDUL99
    @KINGABDUL99 2 роки тому +1

    I know hackers hack the system and crack all the passwords

  • @Simonius95
    @Simonius95 3 роки тому

    Thanks Grant !
    Why aren't the browser hashing the passwords by default? What's the reason in your opinion?
    Greets from Germany

    • @DiekiKondrael
      @DiekiKondrael 3 роки тому

      Hashing passwords would render them useless here, since they have to provide the full original password to the website.

    • @collinsinfosec
      @collinsinfosec  3 роки тому

      Hey! Browsers do encrypt the passwords when stored, but you can decrypt them as well if you had access to the machine. Hashing wouldn't be a viable use case here.

    • @Simonius95
      @Simonius95 3 роки тому +1

      @@collinsinfosec thanks for the response.
      Besides using for example LastPass, is there any other in built Browser solution in sight?

    • @farhanaditya2647
      @farhanaditya2647 3 роки тому

      @@DiekiKondrael I'm sorry, I don't get it. Didn't the browser already send the full password? I mean, that's why you don't have to type it manually.

    • @Simonius95
      @Simonius95 3 роки тому

      ? Do you know sth?

  • @Synceditxboxoffice
    @Synceditxboxoffice 3 роки тому

    hahaha sorry but if you have full access you can directly do the hell lots of things in one go like ssh or list all the things in his own shell and then attack on it or download everything from it and can do more and more and more

  • @mohammedalzamil7191
    @mohammedalzamil7191 3 роки тому

    Nice

  • @chris_32195
    @chris_32195 3 роки тому

    So that is why i lost my epic and steam account...

  • @omkargadave1089
    @omkargadave1089 3 роки тому

    Hi sir.......😍😍😍😍

  • @guilherme5094
    @guilherme5094 3 роки тому +1

    Nice.