~ K D P ~

. . . . . . .

Account Security: New Threats for Google Users

image

Google warns that "protection against account takeovers" is becoming increasingly complex as hackers ramp up their efforts to steal passwords and other critical information.

According to Forbes, losing a Google account can allow hackers to access all other accounts that the user holds outside of Google.

The company noted that losing a Google account could give malicious actors access to other services if the user synchronizes their Chrome browser across devices. Chrome stores a significant amount of data in the user's cloud account, including bookmarks, browsing history, open tabs, passwords, addresses, and payment information, including that linked to Google Pay. If a breach occurs, this data could become accessible to hackers.

Google also reminded users that they can disable Chrome synchronization or adjust it for different types of data. Users can choose not to synchronize passwords or payment information, which enhances security but decreases convenience, as information won't be stored in the cloud.

There’s another issue. As noted by the publication, Google's password manager is essentially just the Chrome password manager, and security experts warn against storing passwords in browsers. This is due to the fact that losing one password can compromise all your accounts, and your passwords face risks from browser attacks that happen quite frequently.

Experts also recommend that users add a passkey and adopt multi-factor authentication, moving away from less secure methods like SMS. The U.S. Cybersecurity Agency has warned Google account holders to "disable other, less secure forms of multi-factor authentication" and "check existing passwords to ensure they are long, unique, and random".

Furthermore, Google suggested checking Chrome synchronization settings and resetting them if necessary to remove outdated data from the cloud storage.

As previously mentioned, Google recently updated the password manager in Chrome. The browser now features a capability that allows it to automatically change weak or compromised passwords. This new feature automates the process: when the browser detects a vulnerable password, it suggests changing it, and on supported sites, it generates a strong option and makes the changes automatically.