1. Current Location: Home >  Router Encyclopedia >  Is the password saved by the browser actually secure? I exported a copy before I could see clearly: 37 plaintext passwords, one per line

Is the password saved by the browser actually secure? I exported a copy before I could see clearly: 37 plaintext passwords, one per line

Is it safe to save passwords in your browser: two copies of passwords in storage, four risk slots, and three reinforcement operation diagrams

Last month,

did a thorough cleaning of my mom's old computer. After cleaning up junk files, I casually opened my browser's password manager, intending to check if her video website account that never logged in was actually saved. I was stunned when I clicked in: 37 articles. The earliest one was saved in 2019, and that year my dad was still using this computer.

Taobao, video memberships, the web versions of two banks, and even the management password for my router's backend—all lying inside. I stared at the list for a long time and thought of a question: over the years, who has used this computer at home? How many times has the repair shop technician used it? What messy software has she installed herself? I can't answer any of them.

first distinguish three things: keys, receipts, and old photos

many people confuse the contents stored in the browser, but in fact, it manages three completely different things. The password database is the key, the account password itself; A cookie is a receipt, a certificate sent by the website that says "this person has logged in." If lost, you can at most log in again. Previously, wrote an article specifically about ; The cache is old photos, copies of webpage image scripts, and clearing them means re-downloading them (this article has discussed how to clear them) .

why is the password database discussed separately? Because losing the first two is a "troublesome moment"; If the keychain is lost, all accounts will be wiped out at once. Every time you click 'Save Password' in your browser, you attach an extra key to that string.

where is this key: one local, one cloud

Chrome. Edge stores the password in an encrypted file under your user directory on Windows, and the encryption binds to the current Windows account. In plain terms: the key to this lock is the password or PIN you use to log in to Windows. You need to log into the system before the browser can unlock and use it; If someone else logs into Windows, theoretically, they can't unlock your data.

this is the first one. The second part is in the cloud—as long as you log in to your Google, Microsoft, or Apple account and have sync enabled, and the cloud still has one copy lying there, you can log in to another computer and get all your passwords back. Convenience is real, but the price is that the cloud account itself becomes a second door.

so, when asked "Is it safe to save passwords in browsers?" there are two main questions: is the Windows account door secure, and the cloud account is secure? The door is secure, and the keychain is secure; One is partially opened, with 37 keys hanging on the doorknob.

I click export once: 37 lines of plaintext

export function is in Settings: Settings → Autofill and passwords→ Google Password Manager→ the three dots in the top right corner → export passwords. When you click, you'll first get a system password or PIN. This verification is for the anti-pedestrian system, then save a CSV file.

I opened it with my notebook and glanced at it: four columns: name, website, username, password. The password column is plaintext, one line per . My mom's Taobao account, video membership, bank web version, and the management password for my home router were all neatly listed in that form. This feature is a legitimate one, officially designed for migration, such as transferring passwords to professional password managers like Bitwarden. But at that moment, my feelings were very direct: this computer could generate a "family password master sheet" at any time, and it had been running on my mom's nightstand for seven years.

after reading it, I immediately deleted that CSV and cleared the Recycle Bin as well. Plaintext documents are such that even ten minutes longer would feel too long.

the only real threats are four openings

online articles about browser passwords like to scare people, listing a dozen or so risks. After sorting them out, I think there are only four that truly hold up, sorted by their proximity to you:

how does block
share a computer someone else logs into your Windows account, Enter the browser and tap the eye icon next to the password to view the plaintext turn on the verification switch. See the next section
export CSV if you forget to delete after migration, the plaintext summary will be left on the desktop or in the download folder and deleted once used. Trojans
steal databases and information theft information theft Trojans will not pop up or extort the recycle bin. Quietly package and send out browser passwords and login receipts Don't install software randomly. See below
cloud account is logged in sync enabled, Google/Apple accounts are the second master key cloud accounts must be validated in two steps

the third mouth says a few more words. In mid-2025, a major event occurred: security vendors revealed that over 16 billion account passwords were packaged and circulated on the dark web, many of which were stolen from entire databases of browsers on infected computers. Microsoft's annual security report also highlights the significant increase in activity of these "information theft trojans." Interestingly, https encrypts the transmission process between you and the website, while lock a segment of along the way; It can't control the passwords already stored on your hard drive. The thief didn't snatch from the street; he went straight inside to carry the safe.

so the idea "I use HTTPS sites everywhere, what's there to fear if I keep my password in the browser?" is actually the most common misunderstanding.

which passwords can be saved and which are kept separately

don't need to cut it all in one go. Comparing my family's actual situation:

__ The HTML105__ far outweighs the drawbacks. Entering passwords every day will only make it easier
reason for saving
a computer used by oneself, with a PIN not simple can be stored casually on everyday websites
Don't store shared computers in shared accounts don't store them in shared accounts just create a separate Windows account. The password library follows the account, so you can't see each other's HTML114__
banks and payment don't enter the browser the official mobile app adds fingerprints, making it easier than any password database
router, NAS backend passwords can be stored provided the password connects all the devices in the home. Both the computer and cloud account must be securely stored
none of the company computers are stored HTML136__ equipment isn't yours; reinstalling, recycling, and remote IT are all routine

fourth line is what I most want to say. Router backend passwords are usually entered only twice a year, but many people save them casually, and I saved them too. But it's not on the same level as video site passwords—behind the background password is the entire home network , where you change DNS, open ports, and kick devices all on that page. Storing it is possible, but the premise is to confirm the door lock first.

I performed three surgeries on my mom's computer

first surgery, start the verification. In Chrome's password manager, there's a switch called "Use Windows Hello when filling in password." After turning it on, you have to check the password or use the PIN again every time you check or auto-fill the password. The switch on my mom's computer is off, so anyone who logs in can check it as they like. It's also recommended to check on your own computer. The path is for settings→ autofill and passwords→ Google Password Manager → settings, just a few lines at the top.

second surgery: inventory clearance. 37 messages were cut down to 9: two from the bank were deleted, and she switched to mobile banking; Those forum members from 2019 and website accounts that were long unused were also removed. I went through the nine passwords I kept one by one, separating the reused password sites.

the third surgery, two-step verification on the cloud account. Her account was linked to her phone number, and the previous verification method was empty, meaning the second door chain wasn't even installed. The task of receiving a verification code on your phone can be done in five minutes.

also changed the management password for her home router. The password for that machine had been lying in the browser for four years. No one could say what the computer had been through, and each change cost one minute. change the backend password a pitfall mentioned in that article is useful here: after changing the password, the browser still auto-fills the old one. Remember to change that record in the password manager, or next time you log in, you'll always get a message of incorrect password and think it's broken.

finish with a clear order: first check if the verification switch is on, then clear the save list, then add two steps of verification for the cloud account, changing the passwords one by one. Password vaults are really convenient, provided you know which door the key is on and that door is actually locked.

Read More


Copyright Notice Scan to read on mobile
All Rights Reserved: 《SHUNOT》 => 《Is the password saved by the browser actually secure? I exported a copy before I could see clearly: 37 plaintext passwords, one per line》
Article URL: https://www.shunot.com/en/lybk/1130.html
Unless otherwise stated, all articles are original by 《SHUNOT》. Reposting is welcome! Please indicate the original URL when reposting, thank you.

Contact Us

Online Consultation: Click here to send me a message

WeChat ID: master_135

Scan to follow