Proton

Is it safe to let your password manager autofill your password?

Struggling to keep track of all your passwords? You’re not the only one. Password managers(new window) exist because it’s difficult to keep track of hundreds of logins and all their various passwords. It’s likely you have saved passwords on your devices for convenience: You might use the password manager built into your browser, software offered by a third party, or one of the cloud-based password managers working across multiple devices like iCloud(new window).

A good password manager can suggest secure passwords(new window), store all of your login credentials safely, and then autofill fields instantly so you don’t need to type in your login details each time. They’re a very useful tool, and one that can help you strengthen your online safety if used correctly. However, there are some safety tips you should be aware of if you want to stay extra secure. In this article we’ll focus on how password autofill can affect your online security.

Is using a password manager safe?

First, let’s understand how a password manager works. Think of your password manager like a bank vault: It’s full of valuable resources, and both you and your service provider are responsible for protecting access to it. You can protect yourself by creating a strong master password or passphrase(new window) and using two-factor authentication (2FA)(new window). Your password manager can then store and protect those passwords.

One of the ways a password manager protects your data is by encrypting it using an encryption algorithm(new window). All your logins, passwords, payment methods, notes and other data will only be accessible to you and the password manager’s servers. Some services offer the more secure option of end-to-end encryption(new window), which prevents the company from accessing your data and ensuring only you can see it. When you’re choosing a password manager, it’s safest to choose one which offers end-to-end encryption, including of metadata(new window). Proton Pass offers end-to-end encryption(new window) which makes all of your data and metadata unreadable when it’s stored in your vault. No-one can access it, not even Proton.

How does password autofill work?

Autofill is a feature in many password managers that lets you automatically populate fields on a website so you don’t have to manually type them in. Fields can include your username and password, but also your bank card details, 2FA code, and other data.

Generally speaking, password autofill is either automated or manual. When autofill is automated, your saved login and password will populate in the relevant fields of a website you’ve saved credentials for. When autofill is manual, your password manager will wait for you to interact with the fields by clicking or typing before it will autofill your password. 

Password autofill risks

Using automated password autofill means you don’t have to think about entering your credentials, but this is risky. Autofill will automatically fill any field on a webpage without your permission. For example, a malicious landing page may have multiple invisible fields which hackers can use to convince your password manager to autofill with your credentials. This can happen without your knowledge, and multiple passwords can be compromised by a single landing page. 

This is a well-known attack called an AutoSpill exploit(new window). In 2023, many password managers were confirmed to have been compromised using this exact exploit, including 1Password, LastPass, Enpass, Keeper, and Keepass2Android. It’s a vulnerability that many password managers simply didn’t have a rigorous enough autofill policy to combat.

But it’s actually incredibly easy to avoid. All you need to do is turn on manual autofill. 

Your password manager will always run background checks, examining the domain and verifying that no phishing elements are present. But using manual autofill creates an extra layer of security because it gives you a chance to check that you’re on the right website. 

Proton Pass uses manual autofill by default and only populates fields on domains you already trust. 

How can I keep my passwords safe? 

Ultimately, it’s up to you to make sure you’re staying safe online. One of the best ways you can do that is to use a trusted, secure password manager. Along with manual autofill, end-to-end encryption, and secure password suggestion, reliable password management software should offer:

The option to create passkeys

Passkeys(new window) make it possible for you to verify your identity online without using a password or passphrase. This means that instead of using a specific password, you can create a digital credential that’s tied to your logged in device. In effect, your password manager becomes the authenticator rather than your password. This is sometimes a more secure option than a password, but not every platform supports them. Proton Pass gives you the option to use passkeys when available.

Proactive protection

In the background, your password manager needs to be aware of data breaches and potentially compromised websites. Pass Monitor in Proton Pass(new window) scans the dark web for you to ensure none of your credentials have leaked, flagging any weak or repeated passwords, and preventing hackers from ever being able to access your account even if they’ve acquired some of your information.

Identity management

Your personal email address is almost like your online passport. A good password manager will not only protect the data and metadata that you save, it’ll help you create email aliases(new window) which forward emails into your inbox. Proton Pass easily generates hide-my-email aliases that can’t be connected to you, putting an extra layer of safety between hackers and your personal email address. If an alias address is compromised, all you’ll need to do is deactivate it.

Proton Pass is the only password manager that offers complete identity protection, using end-to-end encryption built by scientists at CERN. With Proton Pass, you’ll have access to:

Take the first step in protecting your passwords today. Get Proton Pass.

Protect your passwords
Create a free account

Related articles

Cyberattacks aren’t always executed through sophisticated methods like man-in-the-middle (MITM) attacks on public WiFi. Sometimes, they rely on something as simple as looking over your shoulder.  Shoulder surfing attacks are when someone watches you
Proton prioritizes our community’s privacy and data security in every aspect of our business.  To further demonstrate our commitment, we underwent a rigorous external audit and – on May 2, 2024 – received our ISO 27001 certification.  As an organiz
Anyone with an iPhone can now enjoy Proton Drive’s secure and private photo backup capabilities. This feature is gradually rolling out to the Proton community and will be available to everyone by the end of this week. Smartphones have made us all am
From the very beginning, Proton has always been a different type of organization. This was probably evident from the way in which we got started via a public crowdfunding campaign that saw 10,000 people donate over $500,000 to launch development. As
Your online data is valuable. While it might feel like you’re browsing the web for free, you’re actually paying marketing companies with your personal information. Often, even when you pay for services, these companies still collect and profit from y
Password spraying attacks pose a major risk to individuals and organizations as a method to breach network security by trying commonly used passwords across numerous accounts. This article explores password spraying attacks, explaining their methods