24
Password managers: used to swear by browser saving, now I'm second guessing everything
For years I just let Chrome save all my passwords... figured it was fine since I had a strong master password on my laptop. Then about 8 months ago a buddy in a truck stop diner told me his brother got hit by a credential stealer that pulled all his saved browser passwords at once. So I switched to Bitwarden and set up 2FA on everything, even my old trucking dispatch account. Anybody else make the swap and feel like they dodged a bullet, or do you still trust the built-in browser stuff?
3 comments
Log in to join the discussion
Log In3 Comments
brooke712mo ago
honestly I think people overreact to this stuff. I've been using Chrome password saving for like 6 years now and never had a problem. The whole credential stealer thing sounds scary but how often does that ACTUALLY happen to regular people? Most security breaches happen because someone clicks a weird link or downloads something dumb, not because their browser saved their passwords. And honestly if someone has access to your actual computer to run a stealer, you've got bigger problems than just passwords. I still trust the browser stuff, it's simple and it works fine for me.
1
kevin_schmidt972mo agoMost Upvoted
Right there with you on this. I've been using the same Chrome password manager for probably 8 years and never had a single issue with it. The whole credential stealer thing seems more like a theoretical problem for big corporations than something that hits regular folks like us. If someone already has access to your computer to run a stealer, they could probably get your passwords a dozen other ways too.
6
wren_carr2mo ago
Yeah I read this thing from some security researcher a few months back that said browser saved passwords are like leaving your house keys under the mat... sure it works until someone actually looks there. He broke down how credential stealers specifically target Chrome's vault because it's all in one place and easy to extract. I've seen too many stories of regular people getting cleaned out because they never moved their passwords to a dedicated manager. Better to be paranoid than sorry I figure.
0