Geeks2U Promise
We guarantee you'll love our fast, friendly service - or we'll refund your money.
133,572 Happy Customers & Counting
Need tech support?
1300 769 448
Extended hours, 7 days a week
Home  /  geekspeak  /  Google Chrome password “bug” – security flaw or feature?

Google Chrome password “bug” – security flaw or feature?

Login Box

Google’s Chrome browser doesn’t hide your saved passwords, but is that a bad thing?

These days we’re expected to remember dozens of passwords, with security experts insisting that they be long, complicated and unique. Keeping track of all your passwords can become almost a full time job in itself, so any help is much appreciated.

To make life easier, modern web browsers offer to remember your passwords so you don’t need to type them in every time you visit popular sites like Gmail, Facebook and Twitter. Having your browser remember your passwords can be a real time-saver. In some ways it also helps with online security, letting you use long and complicated passwords without the hassle of remembering them all.

The trouble with letting your browser remember your passwords is that if someone gets their hands on your computer they might have easy access to all your passwords. I noticed this a few years ago when I first switched from Firefox to Chrome as my default web browser. This password issue is nothing new, even though it’s made the headlines recently.

Firefox let me set a Master Password, which I needed to enter before I could see my full list of saved passwords. It’s not enabled by default, I needed to open the Security tab in the Preferences and tick “Use Master Password”. Enabling this seemed like a reasonable extra security precaution, even though my computer is locked with a password so I’m not too concerned about people snooping around.

When I first installed Chrome I was frustrated to discover that it’s happy to remember your passwords but doesn’t let you set a Master Password. This means anyone using my computer can type “chrome://settings/passwords” into Chrome’s URL bar and see a full list of my saved passwords. It’s a disturbing sight when you’ve had it drummed into you that your passwords must be kept secret.

Chrome’s lack of a Master Password really bothered me, so I did some research and soon discovered that it wasn’t a “security flaw” but rather a deliberate choice by Chrome’s developers. Their argument is that saving your passwords in your browser creates security risks, whether you use a Master Password or not. If someone has access to your computer and knows what they’re doing they can bypass a Master Password. Using one only lulls people into a false sense of security.

Removing a security feature to encourage security awareness naturally doesn’t sit well with some people. Of course many of them weren’t aware of the issue at all until it made news recently. Now they’re horrified to discover their passwords are in plain view and some are considering abandoning Chrome completely. A Master Password might not keep out determined hackers with access to your computer, but it would at least foil family members trying to sneak a peek at your Facebook password.

Even with the Master Password issue I was still determined to make the switch from Firefox to Chrome, so I decided it was time to investigate third-party password management services such as 1Password, LastPass, KeePass and Roboform. These let you store your passwords securely online or in an encrypted file on your computer, rather than simply saving them in the browser. It’s protected by a Master Password but some online options like LastPass offer the added protection of two-factor authentication.

Now that I use a secure password locker I don’t let any of my browsers remember passwords. You might argue that I’ve swapped one security risk for another, but these password lockers are generally considered a lot more secure than the password features in web browsers. Rather than freak out about Google’s lack of a Master Password, you should also use it as an excuse to reevaluate your approach to password management.


Recent News


In terms of overall storage security, it’s generally tough to beat cloud-based backup, especially if your cloud provider of choice uses an array of storage locations. With the right provider, your files of choice can be backed up in multiple locations, so even if there’s a massive internet outage, or a fire or some other… More 


After starting out as a minor player, FttDP appears destined to play a key role in Australia’s National Broadband Network. The NBN has become a political football over the last few years, with the network design changing several times along the way. As a result it’s hard to know exactly what kind of connection will… More 


The changing of the seasons presents the perfect opportunity to get into good habits when it comes to keeping your business safe. We all have our annual rituals, like changing the batteries in the office smoke alarm when we adjust the clocks for daylight savings. Just like that smoke alarm, there are digital security issues… More 


The chances are pretty good that you’ve used the GPS (Global Positioning System) hardware at some point in the recent past, whether on a dedicated satellite navigation device such as a car-based system, or any of a number of GPS apps available for popular smartphone operating systems. It’s even the basis for popular gaming applications,… More