Is the password saved by the browser actually secure? I exported a copy before I could see clearly: 37 plaintext passwords, one per line

Last month,
did a thorough cleaning of my mom's old computer. After cleaning up junk files, I casually opened my browser's password manager, intending to check if her video website account that never logged in was actually saved. I was stunned when I clicked in: 37 articles. The earliest one was saved in 2019, and that year my dad was still using this computer.
Taobao, video memberships, the web versions of two banks, and even the management password for my router's backend—all lying inside. I stared at the list for a long time and thought of a question: over the years, who has used this computer at home? How many times has the repair shop technician used it? What messy software has she installed herself? I can't answer any of them.
first distinguish three things: keys, receipts, and old photos
many people confuse the contents stored in the browser, but in fact, it manages three completely different things. The password database is the key, the account password itself; A cookie is a receipt, a certificate sent by the website that says "this person has logged in." If lost, you can at most log in again. Previously, wrote an article specifically about ; The cache is old photos, copies of webpage image scripts, and clearing them means re-downloading them (this article has discussed how to clear them) .
why is the password database discussed separately? Because losing the first two is a "troublesome moment"; If the keychain is lost, all accounts will be wiped out at once. Every time you click 'Save Password' in your browser, you attach an extra key to that string.
where is this key: one local, one cloud
Chrome. Edge stores the password in an encrypted file under your user directory on Windows, and the encryption binds to the current Windows account. In plain terms: the key to this lock is the password or PIN you use to log in to Windows. You need to log into the system before the browser can unlock and use it; If someone else logs into Windows, theoretically, they can't unlock your data.
this is the first one. The second part is in the cloud—as long as you log in to your Google, Microsoft, or Apple account and have sync enabled, and the cloud still has one copy lying there, you can log in to another computer and get all your passwords back. Convenience is real, but the price is that the cloud account itself becomes a second door.
so, when asked "Is it safe to save passwords in browsers?" there are two main questions: is the Windows account door secure, and the cloud account is secure? The door is secure, and the keychain is secure; One is partially opened, with 37 keys hanging on the doorknob.
I click export once: 37 lines of plaintext
export function is in Settings: Settings → Autofill and passwords→ Google Password Manager→ the three dots in the top right corner → export passwords. When you click, you'll first get a system password or PIN. This verification is for the anti-pedestrian system, then save a CSV file.
I opened it with my notebook and glanced at it: four columns: name, website, username, password. The password column is plaintext, one line per . My mom's Taobao account, video membership, bank web version, and the management password for my home router were all neatly listed in that form. This feature is a legitimate one, officially designed for migration, such as transferring passwords to professional password managers like Bitwarden. But at that moment, my feelings were very direct: this computer could generate a "family password master sheet" at any time, and it had been running on my mom's nightstand for seven years.
after reading it, I immediately deleted that CSV and cleared the Recycle Bin as well. Plaintext documents are such that even ten minutes longer would feel too long.
the only real threats are four openings
online articles about browser passwords like to scare people, listing a dozen or so risks. After sorting them out, I think there are only four that truly hold up, sorted by their proximity to you:
| how does | block | |
| share a computer | someone else logs into your Windows account, Enter the browser and tap the eye icon next to the password to view the plaintext | turn on the verification switch. See the next section |
| export CSV | if you forget to delete after migration, the plaintext summary will be left on the desktop or in the download folder | and deleted once used. Trojans |
| steal databases and information theft | information theft Trojans will not pop up or extort the recycle bin. Quietly package and send out browser passwords and login receipts | Don't install software randomly. See below |
| cloud account is logged in | sync enabled, Google/Apple accounts are the second master key | cloud accounts must be validated in two steps |
the third mouth says a few more words. In mid-2025, a major event occurred: security vendors revealed that over 16 billion account passwords were packaged and circulated on the dark web, many of which were stolen from entire databases of browsers on infected computers. Microsoft's annual security report also highlights the significant increase in activity of these "information theft trojans." Interestingly, https encrypts the transmission process between you and the website, while lock a segment of along the way; It can't control the passwords already stored on your hard drive. The thief didn't snatch from the street; he went straight inside to carry the safe.
so the idea "I use HTTPS sites everywhere, what's there to fear if I keep my password in the browser?" is actually the most common misunderstanding.
which passwords can be saved and which are kept separately
don't need to cut it all in one go. Comparing my family's actual situation:
| reason for saving | ||
| a computer used by oneself, with a PIN not simple | can be stored casually on everyday websites | __ The HTML105__ far outweighs the drawbacks. Entering passwords every day will only make it easier|
| Don't store shared computers in shared accounts | don't store them in shared accounts just create a separate Windows account. The password library follows the account, so you can't see each other's HTML114__ | |
| banks and payment | don't enter the browser | the official mobile app adds fingerprints, making it easier than any password database |
| router, NAS backend passwords can be stored | provided | the password connects all the devices in the home. Both the computer and cloud account must be securely stored |
| none of the company computers are stored | HTML136__ | equipment isn't yours; reinstalling, recycling, and remote IT are all routine |
fourth line is what I most want to say. Router backend passwords are usually entered only twice a year, but many people save them casually, and I saved them too. But it's not on the same level as video site passwords—behind the background password is the entire home network , where you change DNS, open ports, and kick devices all on that page. Storing it is possible, but the premise is to confirm the door lock first.
I performed three surgeries on my mom's computer
first surgery, start the verification. In Chrome's password manager, there's a switch called "Use Windows Hello when filling in password." After turning it on, you have to check the password or use the PIN again every time you check or auto-fill the password. The switch on my mom's computer is off, so anyone who logs in can check it as they like. It's also recommended to check on your own computer. The path is for settings→ autofill and passwords→ Google Password Manager → settings, just a few lines at the top.
second surgery: inventory clearance. 37 messages were cut down to 9: two from the bank were deleted, and she switched to mobile banking; Those forum members from 2019 and website accounts that were long unused were also removed. I went through the nine passwords I kept one by one, separating the reused password sites.
the third surgery, two-step verification on the cloud account. Her account was linked to her phone number, and the previous verification method was empty, meaning the second door chain wasn't even installed. The task of receiving a verification code on your phone can be done in five minutes.
also changed the management password for her home router. The password for that machine had been lying in the browser for four years. No one could say what the computer had been through, and each change cost one minute. change the backend password a pitfall mentioned in that article is useful here: after changing the password, the browser still auto-fills the old one. Remember to change that record in the password manager, or next time you log in, you'll always get a message of incorrect password and think it's broken.
finish with a clear order: first check if the verification switch is on, then clear the save list, then add two steps of verification for the cloud account, changing the passwords one by one. Password vaults are really convenient, provided you know which door the key is on and that door is actually locked.
