Your favourite motorcycle owners forum or online bank account, they all contain personal information.
If you need to remember a lot of passwords, grab KeePass (Free as in Beer and Speech) and store them all in that. Hell, it'll generate secure passwords for you and let you copy and paste them without ever having to see what they are.
It will run from a memory stick, so no installation required on work / home PCs, and is completely portable.
Bosting.
I'm going to make a browser that passes all categories. #
By Bracken DawsonPosted Monday 15th December 2008 11:45 GMT
’cos on the Mac, passwords are stored on the Keychain, and if you don't unlock your Keychain in the first place, Safari can't decrypt squat.
The default configuration is for your Keychain to be unlocked when you log in, but you can change that easily enough, and set it to to auto-lock under various circumstances, which means you'll be prompted for your Keychain password whenever Safari wants to auto-fill a login form. Hit Cancel and it won't auto-fill a thing.
If memory serves, other auto-fill data is stored in the same way.
By Ken HaganPosted Monday 15th December 2008 12:24 GMT
"Chapin's tests set a high standard ..."
Not on the evidence of this article they don't. How can completing a form when auto-complete is set to "off" be anything other than "go to fail, go directly to fail"? (Apologies to all, myself included, who regard "fail" as the clear sign of an illiterate fool. It just happened to fit on this occasion.)
"...but looking at the results it is tempting to think that users would be well advised never to save passwords for sensitive websites."
You mean there are people who do? Crikey! That's even *more* embarrasing.
By Anonymous CowardPosted Monday 15th December 2008 12:43 GMT
@Mo: Who knows what they tested it on or how? I'm a professional tester and looking at their list of tests tells me that they didn't lock the keychain before performing these tests. It's possible that they don't know how!
It would very be interesting to know which platform(s) these tests were run on (Mac/PC/Linux/all). I believe that they were all run on PC, otherwise the results may have been different (as Mo said, they could lock the keychain).
Suffice to say, there's nothing preventing anyone from coming up with "tests" that prove exactly what they want to prove. If they don't (or won't) tell you how the test was run then the results are meaningless.
My guess is that either this company will soon be selling some kind of "solution" to the problems they've just highlighted OR they only did it for the publicity (Looking at their webpage tells me that they're probably a one or two-man company who need all the publicity they can get).
By Nic BroughPosted Monday 15th December 2008 13:03 GMT
Pleasantly surprised - IE7 scored 5, which is 2 less than Opera and Firefox, 3 more than Safari and Chrome and 8 or 9 more than I was expecting...
I'd be very interested in the results if some of the browsers had some of the regularly used options enabled - "privacy" modes and Firefox+NoScript for example.
By Sceptical BastardPosted Monday 15th December 2008 13:06 GMT
Quote: "Chapin's tests set a high standard but looking at the results it is tempting to think that users would be well advised never to save passwords for sensitive websites."
'Tempting'? 'Advised'? 'Sensitive websites'?
Jeeze! Anyone who stores *any* password in a browser's password manager needs their head examining! In fact, cautious users never store passwords in cleartext anywhere on a computer.
Paris, cos she's stupid too (allegedly)
@TeeCee. Well remembered! You're right, it's pure Gus-speak :)
"How can completing a form when auto-complete is set to "off" be anything other than "go to fail, go directly to fail"?"
Because there's a difference between not saving it when autocomplete is off and not completing it when autocomplete is off.
As an example, Firefox doesn't save the password if autocomplete is off, so it'll never get filled in later. But if I go to the effort of modifying the DOM so that it will get saved (e.g. using the Enable Password Manager bookmarklet) then it's obvious that I do want it autocompleted later. Even then, Firefox doesn't autocomplete it automatically, I have to go to the field, hit the down cursor to select the user, and then hit return.
And I'm quite happy with that because I want to decide which passwords I save instead of some arbitrary decision by the website owner. And, in the event of having a keylogger installed, it's probably more secure.
By grumpyPosted Monday 15th December 2008 13:20 GMT
Shoot, no normal user will do that. It's like... like... like not working as root! Not done. Too much work.
But seriously, security != ease of use. Locking the keychain might well be a theoretical solution, but anything that fails to take human nature into account is not security, just mildly entertaining. Or maybe a CMA. Litigation FTW...
Is only really valid in a default state. So if Keychain is unlocked by default then that's the most appropriate state to test. Same with NoScript on Firefox. All this assuming that the average Joe is dumb (and let's face it, he is).
However, the tests would have been more credible if they had then tested them with the other options that are easily available to the default install.
Just for a flash from the past though, Windows XP was horribly insecure in all tests/attacks largely because its firewall was off by default and that wasn't changed until SP2. XP was appropriatley lambasted for that very reason, so I don't see why other software manufacturer's who have insecure defaults shouldn't be subjected to some derision.
By Steven KnoxPosted Monday 15th December 2008 15:37 GMT
Is Firefox's PM dependent on Javascript or something else disabled by NoScript*? 'Cos the test was on the security of the PASSWORD MANAGERS, nothing else. So unless the answer to the question is "yes" -- which would raise even more questions about the security of Firefox's PM -- then the NoScript plugin should have no effect on the tests whatsoever. And if the answer is "yes", then the tests with NoScript enabled would be irrelevant (as the PM wouldn't work), wouldn't they?
* No, I really don't know -- because I don't use PMs, and I rarely use Firefox.
You can put your browser through their tests yourself on their website. I just put FF2 (with NoScript though as Steven Knox said, shouldn't matter) through and still passed 7 though the results were slightly different from FF3's. It passed "Random Name Attr. Prevents Form Fills" but failed "Multi. Schemes Per User Per Authority".
By Tony PaulazzoPosted Tuesday 16th December 2008 10:07 GMT
>>>Chrome fails to check the location of password requests or the destination to which they are dispatched<<<
What about Firefox? Since anti phishing I would've thought the above requirement would be built, by default, into all browsers. Also, doesn't the master password protect your password list, if not, what's its point?
Admittedly, I don't save passwords to financial or important sites, mainly forums and places like this, and I would never save passwords in IE whatever version, but I thought Firefox's big sell was online security. Is it worth sending a ms to the Firefox team? - they never respond when reporting the crash on exit bug.
Comments on: Browsers fail password protection tests
Like to see.................... #
By Anonymous Coward Posted Monday 15th December 2008 11:29 GMT
Never store passwords in the browser #
By Ash Posted Monday 15th December 2008 11:33 GMT
I'm going to make a browser that passes all categories. #
By Bracken Dawson Posted Monday 15th December 2008 11:45 GMT
Common ancestry #
By David Gosnell Posted Monday 15th December 2008 11:45 GMT
Is that Safari on the Mac, or on Windows? #
By Mo Posted Monday 15th December 2008 11:46 GMT
What? #
By Anton Channing Posted Monday 15th December 2008 11:49 GMT
Is it me? #
By TeeCee Posted Monday 15th December 2008 11:54 GMT
Embarrassingly bad #
By Ken Hagan Posted Monday 15th December 2008 12:24 GMT
Testing #
By Anonymous Coward Posted Monday 15th December 2008 12:43 GMT
Title #
By Nic Brough Posted Monday 15th December 2008 13:03 GMT
Asking for it / @TeeCee #
By Sceptical Bastard Posted Monday 15th December 2008 13:06 GMT
Saw that one coming ... #
By Anonymous Coward Posted Monday 15th December 2008 13:10 GMT
@Embarrassingly bad #
By Dan Posted Monday 15th December 2008 13:13 GMT
Lock the keychain? #
By grumpy Posted Monday 15th December 2008 13:20 GMT
Duh! #
By Gav Posted Monday 15th December 2008 13:26 GMT
This sort of test #
By Matt Posted Monday 15th December 2008 13:39 GMT
Man + dog report #
By Stef Posted Monday 15th December 2008 14:06 GMT
NoScript? #
By Steven Knox Posted Monday 15th December 2008 15:37 GMT
Try it Yourself #
By Paul Posted Monday 15th December 2008 19:29 GMT
Firefox 3.04 and NoScript #
By Kevin Eastman Posted Monday 15th December 2008 23:42 GMT
Saving passwords? #
By Lindsay Posted Tuesday 16th December 2008 00:35 GMT
This title is password protected #
By Tony Paulazzo Posted Tuesday 16th December 2008 10:07 GMT
Remember my password for me? #
By deadfamous Posted Friday 19th December 2008 19:35 GMT