Maybe don't use browsers to store your passwords

Cybersecurity
(Image credit: Shutterstock / song_about_summer)

In addition to practicing poor password hygiene, relying on password managers built into the web browser was another security faux pas highlighted by a recent survey.

Commissioned by access management vendor ThycoticCentrify, the survey noted that more than a third (35%) of the respondents admitted to relying on their web browser to store credentials on their personal and work devices.

"By cracking only one of those devices, an attacker can easily access all the passwords stored within the user’s browser. This makes it so much easier for an attacker to elevate privileges without being detected and gain access to the user’s email, company cloud applications, or even sensitive data,” pointed out Joseph Carson, chief security scientist and advisory CISO at ThycoticCentrify.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Carson argued that even if a personal device is compromised, the attacker can use the authentication information stored in its web browser to analyze the user’s password habits and create all possible combinations of a password using cracking tools to eventually gain access to their well-protected corporate applications and system. 

Knowledgeable ignorance

The survey covered over 8000 knowledge workers from over a dozen countries, to get a handle on risky employee activities.

The research revealed that more than half (55%) of the respondents don’t mind connecting to a mobile hotspot even in a work-based scenario, while 32% have no qualms about connecting to public WiFi networks.

Furthermore, while 23% of the respondents have used personal devices inside their corporate network, 34% admitted to sending work documents to a personal computer.

Surprisingly an overwhelming majority (79%) chose to engage in risky behavior despite knowing the security implications of their actions. 

“When faced with a choice between productivity and cyber security employees will take the easy path and this mostly means sacrificing security,” concludes the research suggesting that businesses must strike a balance between people and technology to properly protect themselves from cyber threats.

Via The Register

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Young woman working at a coffee shop with a laptop
Too many passwords, not enough brain space? Here’s how password managers can improve your life
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
A hand laying out a password
Security attacks on password managers have soared
Man screaming at computer with TechRadar data privacy week logo next to it.
I almost lost my entire online identity – until one tool made all the difference
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
Latest in Security
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
Latest in News
Q Acoustics Q SUB80, QSUB100 and QSUB120 subwoofers
Q Acoustics wants to bring the bass to your post-Oscars movie catch-up
Hospital
Major Oracle outage hits US Federal health record systems
Samsung Galaxy A56 display
Samsung’s new budget handsets are getting One UI 7 before the Galaxy S24 Ultra, and I’m as confused as you are
iPad Pro 13-inch 2024 on a table
The OLED iPad Pro is reportedly less popular than expected – and that could mean these changes to Apple's OLED iPad plans
Sam Porter cradles a baby
Death Stranding 2: On the Beach trailer confirms June release date and an even more harrowing post-apocalyptic world
The Ray-Ban Meta Coperni smart glasses
The new Ray-Ban Meta smart glasses design is an expensive disappointment