The autofill prompt in browsers like librewolf. Or should you save passwords with a manager? I like the aspect of autofilling passwords and certain data.

  • groet@feddit.org
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 days ago

    If you do not set a master password for the browser (that you have to type before the saved passwords are filled in), the despite what others have written, the passwords are not really encrypted. They are, it just doesn’t matter. Because they are encrypted with the password of you OS user. So they are unreadable if someone steals your device or to any other users on your system, but any malware that runs in your user context has full access to the passwords any time you are logged on to the machine.

    Of course if you have malware on your system they can also log your master password as you type it, same with any other password manager. If you unlock the password save, it is available to malware in that moment.

    Also if you use passwords for anything other than websites you should have a password save for those passwords as well so why not have one single save instead of one in your browser and one outside of it.

    Tl:dr saving passwords in your browser is fine but you should absolutely set a master password. External password manager can be more pragmatic compared to browser only.

  • NannerBanner@literature.cafe
    link
    fedilink
    English
    arrow-up
    6
    ·
    3 days ago

    Where’s that comic about the incredible danger of someone having your password to root versus just access to the computer?

    Ah, of course it’s xkcd. https://xkcd.com/1200/

    Passwords (saved in firefox or a firefox derivative) are stored locally, and are encrypted. Passwords in a password manager are stored locally and encrypted, or are stored in the manager’s computer and are encrypted. If someone were to breach your computer’s security, there are probably larger vulnerabilities than the encrypted passwords that are stored locally, as noted in the comic.

    That may not be the entire story when it comes to security, but I think it’s a good start.

  • SayCyberOnceMore@feddit.uk
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 days ago

    Adding to what the others have said, if save your passwords in a password manager application (I’ll volunteer KeePass…), then you’re effectively doing a similar thing, but you can take the passwords with you to other devices.

    So, I disable the browser’s option to save passwords (which avoids a potential security vulnerability) and use KeePass.

    But, I’m working on 2~3 laptops and a phone, so losing the convenience of the browser autopopulating authentication fields is mitigated by having my passwords on multiple devices.

  • HubertManne@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    Im not sure anymore. I know they did not do it well at one point. I personally use online/offline with vaultwarden as online and keepassxp as offline. I keep important things offline only and things that are not important in the online.

  • JoeKrogan@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    For something like lemmy I would save it for convenience as i can always make a new account if something happens but for a bank not a chance. I use an offline password manager in that case.