Why You Should Not Let Your Browser Remember Passwords

 

On one hand, it can seem such an inconvenience to have to type in your credentials when logging into email, banks, Amazon, LL Bean – pick a service and it probably has a username and password.

On the other hand, it can really be an inconvenience to have to repair your reputation, credit rating, or reclaim your identity because a virus pilfered the list of credentials your browser has remembered.

Spyware, viruses and other malicious software are smarter and more threatening then ever before. One need only go to the FBI or Gartner web sites for details.

In addition, your computer can be hijacked to become a spam-bot. This has already happened to a number of users on campus, where their browser knew their email password and was able to use the account to send spam all around the world. This subsequently caused Hudson Valley’s email reputation score to plummet by over 30 points as well as temporarily putting us on blacklists.

As a safety precaution, never allow your browser to remember credentials. If your browser already has passwords remembered, consider performing the following steps.

  • Have your PC professionally cleaned of all known spyware and viruses. You need to do this before you can use this computer for the next steps.
  • Set all new passwords for your online services. This will guarantee that anything known is now invalidated. Make sure this is complete and fully tested before you perform the last step. You may have had your browser remember the password and now you have no idea what it is. Use that to your advantage for the moment and choose a new one.
  • When choosing new passwords for sites don’t use the exact same password for every site, especially if they have the same username. Try to vary the password a little even if you just add the first letter of the business to the end of the password. For example if you have LL Bean, Amazon and National Grid with the same username, the passwords could end in ‘l’, ‘a’ and ‘n’, respectively.
  • Use the documentation below to clear out any previous knowledge of passwords for your specific browser(s):

All public ITS documentation can be found here.

 

Published: Fri, 07 Sep 2012 12:33:44 +0000 by w.jojo