Security Passwords: how to make them strong and keep track of them
Passwords saved in your browser: good enough or a bad idea?
How Chrome, Safari, Edge and Firefox store your logins, when that is fine, when it is risky, and how to check what your browser is holding right now.
The short answer
- Letting your browser save passwords is far safer than reusing one password everywhere, so it is an upgrade for most people rather than a mistake.
- A browser vault is only as strong as the login on the device it sits on, because your operating system holds the key, not a separate master password.
- Turn on the setting that asks for your fingerprint, face or device password before a saved password is filled or revealed.
- Browser storage struggles with shared computers, sharing a login with another person, and moving between the Apple, Google and Microsoft worlds.
- Password stealing malware targets browser profiles specifically, which is the one risk a dedicated manager reduces rather than removes.
Saving passwords in Chrome, Safari, Edge or Firefox is a real improvement on the habit it usually replaces, which is typing the same password into fifty sites. On a personal laptop or phone that only you unlock, with the extra prompt turned on before a password can be filled, it is a sensible place to keep most of your logins. It becomes a bad idea in three situations: a computer other people use, a device with no screen lock or a weak one, and any account you need to share with someone else. The answer depends less on which browser you use than on who can reach the device and what the passwords protect.
What "saved in the browser" actually means
Your browser keeps saved logins in an encrypted database inside your profile folder. The important part is where the key to that database lives. There is normally no master password you type. Instead the key is held by the operating system and handed to the browser automatically once you have signed in to the device.
On Windows that key is tied to your Windows account, so anyone who can sign in as you can decrypt the vault. On a Mac, iPhone or iPad it sits in the keychain, protected by your device passcode, Touch ID or Face ID, and syncs through iCloud Keychain with end to end encryption, meaning the data is scrambled before it leaves the device and Apple holds no readable copy. Android uses Google Password Manager, which offers a similar on device encryption option you have to switch on deliberately.
The consequence follows directly. Your browser passwords are exactly as strong as your device login. A Mac set to log in automatically with no password, or a Windows PC with a four digit PIN that your flatmate watched you type, protects nothing at all.
The three things browser vaults genuinely do well
They sync. Save a password on your laptop and it is on your phone in seconds, with no subscription and nothing to configure. That convenience is why people actually use them, and a password habit you abandon after a week protects nobody.
They warn you about leaks. All four major browsers now compare your saved passwords against known breach data and flag the ones that turn up. The check is designed so your actual password never leaves the device: only a short fragment of a scrambled version is sent. There is more on reading those warnings in how to check whether your password has already leaked.
They refuse to autofill on the wrong domain. This one is underrated. Your browser saved the password against the exact site address, so on a lookalike domain like paypa1-secure-login.com nothing appears. That silence is a genuine warning signal, and it works even when you are tired and the phishing message is convincing.
Where browser storage falls short
Shared and borrowed devices are the biggest gap. Browser vaults assume one human per operating system account. If your family shares a single Windows login, everyone shares your passwords.
Information stealing malware is the second. Browser profiles are the most valuable folder on a home computer, so the malware sold to criminals is built to grab them along with session cookies, which let an attacker resume your logged in session without needing your password or your two factor code at all. Browsers have been tightening this with encryption that binds the vault to the browser itself, but any program running as you on an infected machine is still a serious threat. Most of that malware arrives through a fake download or a bad add-on, so read up on risky browser extensions before you install one.
Third, browser vaults have no real answer for handing a login to another person, which pushes people back to text messages. There are better routes in sharing a password without texting it.
How to see everything your browser is holding
Do this once, on your main computer. It usually takes under ten minutes and most people find twenty forgotten accounts.
- Open the list. In Chrome, type chrome://password-manager/passwords in the address bar. In Edge, use edge://settings/passwords. In Firefox, use about:logins. On a Mac, open the Passwords app or Safari settings, then Passwords. On an iPhone or Android phone, the list is in Settings rather than the browser, under Passwords or Google.
- Sort by site and delete anything for a service you no longer use. Every stored password is a liability with no benefit once the account is closed.
- Open the checkup section, called Password Checkup, Security Recommendations or Breach Alerts depending on the browser, and deal with anything marked reused or compromised.
- Turn on the re-authentication setting so a fingerprint, face scan or device password is required before filling. In Firefox this is the Primary Password option, which is the only browser setting that adds a real second secret.
- Check which account the vault syncs to, and make sure that account has two factor authentication on it. Whoever controls your Google or Apple account controls the vault.
Browser vault or dedicated manager
| Question | Browser vault | Dedicated manager |
|---|---|---|
| Unlocks with | Your device or account login | A separate master password you type |
| Works across Apple, Google and Windows | Awkward, needs extensions and workarounds | Yes, by design |
| Sharing a login with family or staff | Limited or none | Shared folders, revocable |
| Stores card details, notes, recovery codes | Cards and addresses only | Anything |
| Cost | Free | Free tiers exist, paid plans are common |
| If your device is infected | Profile is a prime target | Vault is locked when the app is locked |
A dedicated password manager wins on shared devices, mixed ecosystems and anything work related. For a single person on a single brand of device, the browser is a defensible choice.
What to check first
Start with the device login rather than the passwords. Set a screen lock with at least six digits or a proper password, turn off automatic login, and set the screen to lock after five minutes of inactivity. That single change decides how much your browser vault is worth. Then turn on the re-authentication prompt, clear out dead entries, and fix anything the breach checker flagged, beginning with the password to your email account.
Common questions
Can someone sitting at my unlocked computer read my saved passwords?
To display a password in plain text, every major browser now asks for your device password, fingerprint or face first. They can still sign in to your accounts, though, because autofill usually works without that prompt. An unlocked screen is the real exposure.
Are passwords saved in Chrome or Safari sent to the company in readable form?
They are encrypted before they sync. Apple's iCloud Keychain is end to end encrypted by default, and Google offers an on device encryption option that locks the vault to a key only you hold. Without that option, Google can technically access the data, which matters if your Google account is ever taken over.
What happens to my saved passwords if I switch from Chrome to Firefox, or Android to iPhone?
Every browser can export to a CSV file and import one, so nothing is trapped. The catch is that the export file is plain readable text, so create it, import it immediately, then delete it from the downloads folder and the trash.
Should I use both a browser vault and a password manager?
Pick one as the place of record, or you will end up with two different passwords for the same site and no idea which is current. Most people who install a manager turn the browser's own save prompt off the same day.