+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

The passwords your web browser saves for you are not safe at all

Jul 28, 2015, 20:32 IST

It turns out, your saved web passwords are less safe than you might think.

Advertisement

I was having some trouble logging into the Tech Insider content management system to work on a story, and asked one of our development team staff to have a look. He asked if I was sure I had typed in my password correctly. I said I was, but he looked dubious.

He right-clicked the password box, which of course only displayed asterisks (seen below):

Tech Insider

He then clicked "Inspect Element," which brought up the site's code:

Advertisement

Tech Insider

Looks like a mess, right? It is. But look closely and you'll see the string "type="password"". He deleted the word "password" after "type," like so:

Tech Insider

That instantly revealed my password in the content entry box:

Tech Insider

Advertisement

"Is that your password?" he asked. It was (I've obviously changed it in the example above). I was stunned - the whole thing took less than five seconds.

(Note: this method works in Google Chrome. Other browsers will have somewhat different approaches, but I'm not here to provide a training manual on password-snatching.)

This trick works on Google, Facebook, Amazon, TD Bank and every other site I've tried.

The danger here is that many people have their passwords saved on their computers, so that password field will auto-populate the minute a page opens.

In a perfect world people would only save passwords on computers with motherboards soldered directly onto the steel walls of bio-locked vacuum chambers, like the one Ethan Hunt here is descending into in the iconic "Mission: Impossible" scene.

Advertisement

Give Tom Cruise a scuba tank though and he is there.Paramount

But how many people actually live that way?

I regularly leave my laptop unattended for short periods in rooms with friends and coworkers. My reasoning is that I trust all of those people individually, and if one of them were tempted to do something nefarious, the risk of my returning to catch them in the act would deter them from trying to log into any of my accounts on my device. And if they did, they probably wouldn't have time to do much more than post an embarrassing Facebook status.

Tech Insider

A trick this quick for learning someone's password entirely changes the game. A person could, with a few taps on a keyboard, learn your password while you're out of the room, and then erase all trace of what they'd done. Then they could access your account from any device, any time, anywhere, without you knowing. Trust me: as someone who once had several of my accounts remotely breached, this is something you definitely want to avoid.

In the short term, you can mitigate this danger by setting up two-step verification on all your accounts, locking your computer every time you step away, and using separate passwords on separate accounts. But in the long term, this seems like an obvious flaw for web developers to address.

Advertisement

I'm not the first person ?to write about this exploit, and we shouldn't have to wait until celebrities fall victim to see it fixed. Web security is meant to protect the way people use the internet in the real world, not in an unrealistic "perfect" world.?

NOW WATCH: How To Make Sure You Never Forget Your Passwords Again

Please enable Javascript to watch this video
You are subscribed to notifications!
Looks like you've blocked notifications!
Next Article