Hi !
I recently moved from Windows 11 to Zorin OS. I use Microsoft Edge and Google Chrome. On Windows, when I wanted to auto-complete a save password, user authentication was required on both. I haven't found how to do this on Zorin OS. If I go in the password managers of both navigators, I can see them by clicking on the eye, without user authentication required. So : are my passwords really protected on my computer ? Is there a way to change that ?
Thanks for your answers
You can setup 2FA, but I am not sure if this affects clicking the eye icon...
You can use password mangers rather than saving the passwords as autofill in the browser like 1Password or KeePassXC.
The Windows Credential Store is part of the Windows Data Protection API (DPAPI). Browsers are far more tightly integrated into Windows OS, with a lot of 'cooperation' between browser developers and Microsoft, allowing for the Credential Stores security.
On GnuLinux, since there is hefty security on user account access, another party would either need access to that password to access the desktop, then access that Eye icon in your browser at that page; or access it covertly after you applied your own password... perhaps if you left the machine unattended in order to hunt down some coffee.
That eye icon is present on my phone apps without other authentication as well.
Security is not an absolute binary state: protected and unprotected. You need to think of it within a context. The passwords themselves are probably stored securely and are being unlocked when you log in to your account. But if there's a chance someone might sneak up on your computer and click that "show password" button, then you should just lock the computer when you are walking away from it.
I would also highly encourage you to use a password manager, such as KeePassXC. The main downside with using a third-party solution would be synchronize the database across devices, but in my opinion the benefits are more than worth it. Plus, there are cloud-based alternatives, such as Bitwarden or Proton Pass.
1 Like
I see, thanks... To complete: on my phone, if I try to access the Google Password Manager and then show one of my password, it asks me the lock code of my phone to show it.
I'll think about Proton Pass maybe, thanks !
1 Like
I understand your worry about security of passwords. A while back I installed Chromium Browser (just like Chrome)but didn't like the password system. I reverted to Firefox, where in Settings> Privacy & Security> you can set a Primary Password that is required to view the folder or an eye icon. I am much happier with that.
3 Likes