Skip to main content

1.5% of Chrome users’ passwords are known to be compromised, according to Google

password
Image used with permission by copyright holder

1.5% of passwords used in Chrome are unsafe and have been released in data breaches, according to new information from Google.

In February, a new feature was introduced to the Google Chrome browser which checks whether users’ passwords are secure. Password Checkup is a free download that scans a database of 4 million compromised passwords and informs users if their password is among them and they need to change it. The database of passwords is collated from known third-party data breaches and when a user enters their password, it is checked against the list.

Now, Google has released eye-opening stats gathered from Password Checkup. Over 650,000 users have downloaded the tool, which has flagged more than 316,000 passwords as unsafe. That’s 1.25% of sign-ins which were made using passwords known to be compromised. This included sign-ins for “some of [users’] most sensitive financial, government, and email accounts” and covered “shopping sites (where users may save credit card details), news, and entertainment sites.”

A particular problem was people reusing passwords. People were more likely to reuse passwords outside of the most popular sites — 2.5 times more likely, in fact. The reuse of passwords makes it much easier for hackers to access accounts using a technique called credential stuffing.

Even when users were warned by Password Checkup that their passwords had been compromised, only 26% of them opted to reset their passwords. On the plus side, 60% of new passwords entered were relatively secure and would require more than a hundred million attempts to guess randomly. Previously, less than 20% of new passwords achieved this level of security.

Google announced it would be adding new features to make Password Checkup, including a comment box for giving quick feedback and more data privacy controls. The extension should never be able to learn the passwords of the users it checks for, but now users can opt out of all anonymous telemetry reports.

If you are concerned that an account you use may have been compromised, you can use the free tool HaveIBeenPwned to check. And if you are looking for a way to keep your passwords secure and to create secure passwords quickly, then you can use a password manager such as LastPass or 1Password.

Editors' Recommendations

Georgina Torbet
Georgina is the Digital Trends space writer, covering human space exploration, planetary science, and cosmology. She…
Update Google Chrome now to patch this critical security flaw
A MacBook with Google Chrome loaded.

You might want to update your Google Chrome web browser right away. Google recently issued a critical security update for Chrome, patching up 11 security issues, including two zero-day vulnerabilities that were exploited in the wild.

Released on September 13, Google first listed the patched vulnerabilities on the Chrome Releases blog. Full details are being withheld for security reasons, as Google wants a majority of users to update first.

Read more
Update Google Chrome now to protect yourself from these severe vulnerabilities
A MacBook with Google Chrome loaded.

You might want to update Google Chrome as soon as you can, as Google has discovered some severe vulnerabilities in the web browser.

Google just issued a total of nine security fixes, covering all desktop versions of Chrome on all operating systems, with Chrome version 92.0.4515.159. The fixes were contributed by activists and external researchers.

Read more
A zero-day Google Chrome security flaw requires you to update now
Google Chrome opened on a laptop.

Google released an update to its Chrome browser for Windows and Mac users, and the internet giant strongly recommends that users apply the update as soon as possible. The update contains 14 security fixes -- including a zero-day security flaw -- that if left unchecked would leave the system vulnerable to attacks. Google categorized these fixes as critical, high, and medium importance.

Windows and Mac users who also surf the internet with the Chrome browser will want to make sure that they're on version 91.0.4472.101. To make sure that you're on the latest build of Chrome, launch your browser and then click on the three dots stacked vertically at the top right. Navigate to Settings, and then click About Chrome. From there, you'll be able to view the Chrome version number, and you can update the browser if it wasn't automatically updated in the background.

Read more