Advertisement
Promo

Security management Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Browsers fail password-management security tests

Matthew Broersma ZDNet.co.uk

Published: 16 Dec 2008 17:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google's Chrome browser and Apple's Safari have received poor marks in a new set of tests evaluating the security of password-management features in five popular web browsers.

Chapin Information Services (CIS), which published its test results on Friday, said Chrome 1.0's password manager failed all but two of 21 tests — a score matched by Apple's Safari 3.2. Microsoft's Internet Explorer 7 scored slightly better, passing five of the tests, while Opera 9.62 and Firefox 3.0.4 both passed seven of the tests.

"Safari and Chrome are essentially tied for the worst password manager built into a major web browser," CIS said in a statement.

Of the tests failed by Chrome's password manager, three failures were highlighted by CIS as particularly risky, as they mean the browser could allow a malicious website to steal passwords stored in the password manager.

CIS said that, firstly, Chrome failed to check the path to which passwords are sent; secondly, failed to check the domain from which passwords are requested; and, thirdly, did not perform well in handling invisible form elements. Chrome was the only tested browser to fail all three of these tests, CIS said.

None of the browsers passed the first test, which covered checking the path when passwords are retrieved. Only Opera and Firefox passed the second test, to do with preventing passwords from being delivered to a domain different from the one the password was delivered to when it was saved.

The third test related to whether the browser prevents passwords from being delivered to a form that the user can't see — for example, from being used to fill out a login form on a web page that has its display property set to 'none'. Chrome and Firefox both failed this test, according to CIS.

Opera's password manager came closest to getting around the three tests, as it has the ability to deactivate invisible form elements, and options that partly addressed the other two issues, CIS said.

Safari addressed the problem of invisible forms, but passed only one other test: that of requiring user interaction to save a password.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
10 out of 10 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:












Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters