autofill forms cybersecurity risks

Browser Autofill Could Put Your Data At Risk

Filling out online forms is annoying.

That’s why most browsers offer to remember your name, address, phone number, email, passwords, and even credit card information for you. That way, the next time you shop online, everything appears with an easy click.

You’ve likely seen these form fill options pop up. It’s extremely convenient and automates a repetitive, manual task. It also means your browser may be storing a surprisingly detailed collection of your personal information in one place.

Browser autofill isn’t necessarily dangerous, but understanding what you’ve saved—and where you’ve saved it—is an important part of staying cyber-safe.

Depending on your browser and settings, autofill can remember information like:

  • Your full name
  • Home and work addresses
  • Phone numbers
  • Email addresses
  • Credit and debit card information
  • Usernames and passwords

That can save a lot of repetitive typing!

Yet what would happen if somebody else accessed that device? What if a coworker could autofill your bank information, or a third-party vendor discovered your home address without your consent? If someone gains access to an unlocked computer or browser profile, they may find much more than your search history waiting for them.

When you’re working out of a café, how often do you leave your laptop unlocked for a moment while you use the facilities or grab a cup of coffee?

Maybe someone takes the opportunity to sneak through your computer. They open a shopping website and clicks inside the address field…where your browser immediately offers to autofill your full name, address, phone number, and email address.

Depending on your browser configurations, it may also offer other saved information.

Nobody had to “hack” anything. You already told your browser to remember it and autofill in your relevant data. This becomes particularly important on shared computers, family devices, or any other digital tool that someone else can physically access.

There is another reason to pay attention.

Phishing websites are designed to look legitimate. If you land on a fake login or checkout page, seeing your browser offer to fill information automatically can make the page feel safer than it really is. On top of that, threat actors can secretly embed invisible pages into a website that include form fills you cannot see. When you allow your browser to autofill a login and password, it may also provide your credit card information to that secret, embedded page. You never even realize that your information was taken until the fraudulent activity shows up on your bank statement.

Don’t assume that an autofill suggestion means your browser has verified the website’s security. Before entering personal information, check the web address and make sure you’re actually visiting the company portal that you intended to visit. Safe, legitimate websites should show HTTPS:// in the address bar, instead of HTTP:// to indicate that it’s Secure (really, that’s what the S stands for!).

In other words, you should always check what information you include and where you mean to include it.

Using unique passwords is extremely important, and you certainly don’t want to go back to memorizing dozens of them or keeping them written on a sticky note! On the other hand, we’ve demonstrated why saving them to your browser presents a risk, too.

A dedicated password manager, or the protected password-management features built into modern browsers, can make strong, unique passwords much easier to use. Lock up these digital “vaults” with a secure master password and they can successfully store, fill and even generate all of your other unique passcodes.

For really sensitive accounts, you should also implement multi-factor authentication, which requires a secondary form of verification to complete a login. That stops someone from logging in through a stolen password alone!

Open your browser settings and see what information you’ve already saved. You may be surprised what it knows about you!

  • Delete old addresses and expired payment cards.
  • Remove information you no longer need.
  • Check which passwords are stored and make sure you aren’t still reusing the same password across multiple accounts.
  • Most importantly, don’t save sensitive information on public or shared computers.

If a website offers to remember something and you don’t need that convenience, simply say No.

Autofill is a useful feature, and you don’t need to turn it off completely in order to stay safe. You just need to remember what you ask your browser to remember for you.

Every so often, take a few minutes to review what’s stored, protect your devices, and think before allowing your browser to save any additional information.

Autofill can save you a few seconds. Just make sure those few seconds of convenience aren’t giving someone else easy access to information that you’d rather keep private.

Related Posts