this post was submitted on 30 Apr 2026
15 points (100.0% liked)

Cybersecurity

9974 readers
47 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
 

The autofill prompt in browsers like librewolf. Or should you save passwords with a manager? I like the aspect of autofilling passwords and certain data.

you are viewing a single comment's thread
view the rest of the comments
[–] eerongal@ttrpg.network 10 points 2 weeks ago (1 children)

Saving the password in your browser is using a password manager; you're just using the one built into your browser. The safety and security of using any individual password manager is pretty much up to how secure that particular password manager is, but generally speaking they all store passwords encrypted.

Ones built into a browser have the added attack vector of being potentially vulnerable from the browser itself vs a stand alone manager, but if you use a plugin for your favorite password manager they likely share a pretty similar attack vector possibility.

Either way, using a password manager is infinitely better than reusing passwords, so this is really just a long winded way of saying "no, not really".

Dedicated password managers usually come with more security, control, and features, but you're generally going to be fine using the one built into your browser.

[–] BentiGorlich@gehirneimer.de 1 points 2 weeks ago (1 children)

Well I mean only when you have a master password for them, otherwise even if they are encrypted, one can just decrypt them like the browser would. Am I mistaken? Because in my mind storing passwords in browser is basically a password manager without the encryption...

[–] eerongal@ttrpg.network 1 points 2 weeks ago

password managers in the browser still store them encrypted. They usually authenticate via a passkey, in-built security in the OS like windows hello, or through other services such as SSO through google; That said, if you have them on auto-pilot with this authentication, anyone with access to the device can theoretically access them, though to actually view them in the password manager they usually require you to authenticate.

Browser password managers are sorta less secure than a third party one, assuming you turn on all the convenience features to make your life easier, but a lot of third-party password managers have the same convenience features a lot of the time anyways.