Use Free Built-In Tools to Check Which Sites Have Your Saved Passwords

You have passwords stored in a bunch of sites you cannot even remember anymore. There is nothing to worry about – it is simply the nature of being online for a few years. Good news for you – you do not have to find them yourselves because your browser already knows about that. 🕵️‍♀️

All popular browsers Chrome, Safari, and Firefox have password managers. They are rarely used. All users do is clicking the "save password" prompt and continuing doing what they were doing before. Years passed and now you have tons of passwords you cannot even remember you registered. Your Wattpad account from high school? Saved. Free trial of some streaming services which you once used? Yes, saved again.

It is easy to check the passwords. In Chrome, you need to click the three dots in the top right corner and go to Settings > Autofill > Password Manager. Then, you will see the list of sites where your passwords were stored. Every row consists of the name of the site, your username, and hidden password which can be revealed by clicking the eye icon. On Safari on Mac, it can be found in Preferences > Passwords. On Firefox, it is Logins and Passwords in the Settings menu.

The list may surprise you a little. People usually find that there are from forty to eighty passwords stored. There are even people who have over two hundred stored passwords. You registered on a random forum, shopping site, service trial – every site was saved. The problem is – these sites get breached relatively often. The moment a company which you registered with in 2017 gets hacked, your email-password pair gets into the database which is sold on the dark web. Moreover, if you used the password on any other site, those sites are vulnerable as well.

Now, let us talk about Google's Password Checkup tool. Chrome has "Check passwords" button in the same page as password manager. You click it and Google checks your saved credentials with their massive database of known password breaches. The procedure lasts no more than ten seconds, after which you know exactly which of your passwords got hacked, which you used on multiple sites, and which are stupid. And the result is quite embarrassing. 😅

Firefox has something similar in the form of Firefox Monitor. You can visit monitor.firefox.com, enter your email and the website will check your email against hundreds of known data breaches and notify you about how many times your information has been exposed. There is even an equivalent from Apple which can be found in iOS and macOS Settings app under Passwords.

This is the part people do not want to hear. The thing is – you need to change the passwords immediately. Not tomorrow. Not next week. Right now. Showing a problem is just half the task completed. Disregarding the warning is like being told that your "check engine" light is on and covering it with a sticker. It looks better but the engine dies anyway.

You should start with accounts which matter the most. Your email is like a skeleton key to everything. If somebody hacks into your Gmail account, he or she will be able to reset password to any other account you use. After that comes your banking, social media accounts, and everything else. With the help of password manager, you can generate unique passwords for each site. They should be long and random enough. "x7#mK9$pL2vQ" sounds way better than "password123" or your pet's name with your birth year.

Two-factor authentication should be activated wherever it is possible. That means that even if somebody gets access to your password, they would still need a code sent to your phone to log in. Two-factor authentication is supported by Instagram, Snapchat, Discord, and almost every major platform now. It requires you a little bit of extra time to log in – about fifteen seconds.

Using browser password manager is definitely not a best option for password storage. Security experts already noted that storing passwords in Chrome allows everybody using your computer to see them. Using dedicated password manager such as Bitwarden or 1Password provides you an extra layer of encryption which will work on all your devices and browsers. Being open-source and free, Bitwarden could be a good choice for students. However, even using Chrome password manager is definitely better than reusing the same password everywhere. It is the difference between leaving your front door open and closing but not locking it. Neither solution is perfect but one is clearly worse.

All you need to do is to spend five minutes today. Open your browser settings, look at the password list, run the checkup tool, and change the passwords which came out to be bad. Trust me, your future self will be grateful in case the next big data breach happens and you will not have to reset your passwords at 2 AM. 🙏

Post a Comment

0 Comments