Chrome, Safari fail password security tests

Analysis
Dec 16, 20082 mins

When it comes to browsers, password security is simply not their strong suit, and that’s especially true for Google’s Chrome and Apple’s Safari. While every top browser today–including IE 7, Opera 9.62, Firefox 3.04, Safari 3.2 and Google’s Chrome–do a poor job of protecting user passwords, Chrome and Safari are the worst, according to recent tests conducted by Chapin Information services.

The tests, which examined 21 separate password security issues, found all of the browsers lacking, with the best browsers–Opera and Firefox–passing just 7 of 21 tests. In comparison, IE passed 5, while Chrome and Safari passed just 2. Critical to password security, the firm says, is the ability to secure against three major problems, that when combined, allow password thieves to take passwords without the user’s knowledge:

  • The destination where passwords are sent is not checked.
  • The location where passwords are requested is not checked.
  • Invisible form elements can trigger password management.

Chapin says Opera is currently closest to solving the three problems, since it deactivates invisible form elements, limits saved passwords to a single page and offers partial destination checking. But Chrome is among the worst. As Chapin concludes:

These three problems, combined with seventeen others so far identified in Chrome’s password manager, form a toxic soup of potential vulnerabilities that can coalesce into broad insecurity.

Perhaps Google should have let Chrome bake a bit longer before it rolled it out of beta. Password insecurity is no way to endear enterprise users to Google.