	{"id":591,"date":"2008-12-16T10:21:46","date_gmt":"2008-12-16T09:21:46","guid":{"rendered":"http:\/\/blog.intego.com\/?p=591"},"modified":"2008-12-16T10:21:46","modified_gmt":"2008-12-16T09:21:46","slug":"safaris-password-manager-not-secure","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/","title":{"rendered":"Safari&#8217;s Password Manager Not Secure"},"content":{"rendered":"<p><img src=\"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg\"><\/p>\n<p>Robert Chapin of Chapin Information Services has <a href=\"http:\/\/www.info-svc.com\/news\/2008\/12-12\/\">analyzed how password managers work<\/a> in a number of web browsers, and has found that Safari comes in tied for &#8220;last place&#8221;. Chapin tested Opera, Firefox, Internet Explorer, Safari and Google Chrome, and found that, while most of the browsers failed most of his tests, Safari only passed two of them. All told, this is a &#8220;toxic soup of potential vulnerabilities that can coalesce into broad insecurity.&#8221;<\/p>\n<p>All modern browsers have password managers, that work alone or with other parts of the operating system to record user names and passwords, and enter these automatically in fields on web pages. (On Mac OS X, Safari works with Keychain Access to manage passwords securely.) Password managers should only send user names and passwords to forms on pages that match the domains on which they were recorded, and not send this information to other websites without informing users. Yet Chapin found that this is often not the case.<\/p>\n<blockquote><p>\nAmong the problems are three in particular that, when combined, allow password thieves to take passwords without the user&#8217;s knowledge.<br \/>\n\t1.\tThe destination where passwords are sent is not checked.<br \/>\n\t2.\tThe location where passwords are requested is not checked.<br \/>\n\t3.\tInvisible form elements can trigger password management.\n<\/p><\/blockquote>\n<p>While Chapin analyzed Windows browsers, we ran a series of tests of the current version of Safari for Mac OS X (3.2.1) using Chapin&#8217;s <a href=\"http:\/\/www.info-svc.com\/news\/2008\/12-12\/pm-evaluator\/\">Password Manager Evaluator<\/a>. We obtained the exact same results for Safari for Mac OS X as he reports for the Windows version.  <\/p>\n<p>What users should do is be very careful about allowing Safari to enter a user name and password automatically if they are on a site that seems unfamiliar. As <a href=\"http:\/\/www.macworld.com\/article\/137540\/2008\/12\/safari_passwords.html\">Macworld reports<\/a>, hackers did this with &#8220;a fake password entry form on a MySpace page. Because both the fake and real login forms were on the myspace.com domain, browsers like Firefox could be tricked into automatically sending login information to the fraudsters.&#8221; It seems that Safari is vulnerable to this strategy as well. While using a password manager is practical and saves time &#8211; and allows users to create unique passwords for different sites without needing to remember them &#8211; it is clear from this study that such a practice is fraught with danger.  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Robert Chapin of Chapin Information Services has analyzed how password managers work in a number of web browsers, and has found that Safari comes in tied for &#8220;last place&#8221;. Chapin tested Opera, Firefox, Internet Explorer, Safari and Google Chrome, and found that, while most of the browsers failed most of his tests, Safari only passed [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7,13],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Robert Chapin of Chapin Information Services has analyzed how password managers work in a number of web browsers, and has found that Safari comes in tied\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Safari&#039;s Password Manager Not Secure - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Robert Chapin of Chapin Information Services has analyzed how password managers work in a number of web browsers, and has found that Safari comes in tied\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2008-12-16T09:21:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/\",\"name\":\"Safari's Password Manager Not Secure - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#primaryimage\"},\"datePublished\":\"2008-12-16T09:21:46+00:00\",\"dateModified\":\"2008-12-16T09:21:46+00:00\",\"description\":\"Robert Chapin of Chapin Information Services has analyzed how password managers work in a number of web browsers, and has found that Safari comes in tied\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Safari&#8217;s Password Manager Not Secure\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Safari&#8217;s Password Manager Not Secure\",\"datePublished\":\"2008-12-16T09:21:46+00:00\",\"dateModified\":\"2008-12-16T09:21:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#webpage\"},\"wordCount\":381,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg\",\"articleSection\":[\"Apple\",\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Robert Chapin of Chapin Information Services has analyzed how password managers work in a number of web browsers, and has found that Safari comes in tied","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/","og_locale":"en_US","og_type":"article","og_title":"Safari's Password Manager Not Secure - The Mac Security Blog","og_description":"Robert Chapin of Chapin Information Services has analyzed how password managers work in a number of web browsers, and has found that Safari comes in tied","og_url":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/","og_site_name":"The Mac Security Blog","article_published_time":"2008-12-16T09:21:46+00:00","og_image":[{"url":"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/","name":"Safari's Password Manager Not Secure - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#primaryimage"},"datePublished":"2008-12-16T09:21:46+00:00","dateModified":"2008-12-16T09:21:46+00:00","description":"Robert Chapin of Chapin Information Services has analyzed how password managers work in a number of web browsers, and has found that Safari comes in tied","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Safari&#8217;s Password Manager Not Secure"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Safari&#8217;s Password Manager Not Secure","datePublished":"2008-12-16T09:21:46+00:00","dateModified":"2008-12-16T09:21:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#webpage"},"wordCount":381,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/safaris-password-manager-not-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/images\/safari.jpg","articleSection":["Apple","Security &amp; Privacy"],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-9x","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/591"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=591"}],"version-history":[{"count":1,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/591\/revisions"}],"predecessor-version":[{"id":30817,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/591\/revisions\/30817"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}