My Account
HOME CUSTOMERS Manage Account Add a Device Download PC Matic
BUSINESS CUSTOMERS Business Login
Company
PC MATIC About Us Careers Industry Recognition Leadership
STAY UP-TO-DATE Events TechTalk Podcast Commercials
Blog
Contact Us
CUSTOMER SUPPORT Home Support Business Support
CONTACT SALES Talk to Sales
For Home
Antivirus Security
PC Matic Complete Security Award-winning protection from modern security threats, VPN wifi security, PC performance optimization and more.
PC Matic VPN Cutting-edge Virtual Private Network that keeps your information private.
Products
Antivirus PC Matic VPN Identity Protection PC Matic Privacy Support Unlimited
Threat Awareness
How PC Matic Protects You SuperShield Allowlist
For Business
Business Protection
PC Matic Pro Proactive security and remote management for advanced cyber threats.
PC Matic for SMB Simple & efficient American-made cybersecurity for small and medium-sized businesses.
Solutions
Allowlisting Script Enforcement Device Control Patch Management Remote Tools Integrations Server Security
Learn More
Resellers Affiliates Resources Case Studies
For Federal
Partners
Partner Programs
Managed Service Providers Offer simple & efficient application allowlisting with zero contracts or minimums.
Channel Partners Lets deliver next level, zero trust endpoint protection that people and organizations need, together.
Explore Partnerships
Affiliate Partners
Resources
Resources
Resource Center The best source for case studies, reports, data sheets and all of the latest digital content from PC Matic.
PC Matic Blog Stay up-to-date with the latest news around cybersecurity, scam alerts, helpful tips and more.
Knowledge Resources
Case Studies Data Sheets User Guides White Papers
Blog Resources
Business Security Home Security Cyber News Scam Alerts
Support
Customer Service
Home Support The only place for PC Matic home customers to get trusted technical support.
Business Support Premiere support for business, government, enterprise and education customers.
Learn More
Getting Started Knowledgebase Tech Support Scams Fake Virus Scam The Cyber Scam Report Town Hall Sessions
Security Tools
Password Generator Internet Speed Test What Is My IP?
Company
PC Matic
About PC Matic Learn more about how we began, and our mission to change the security industry.
Careers Grow with us and experience great employee benefits in a work from home environment.
Learn More
Industry Recognition Leadership Commercials
Stay Up-to-Date
Newsroom Blog Events TechTalk Podcast
My Account
Home Customers
My Account Add a Device Renew Subscription Download PC Matic
Business Customers
Business Login Business Support
Buy Now Buy Now Buy Now
Safe + Secure
PC Matic Complete Security
Products
Antivirus
PC Matic VPN
Identity Protection
PC Matic Privacy
Support Unlimited
Threat Awareness
How PC Matic Protects You
SuperShield Allowlist
Business Protection
PC Matic Pro
PC Matic for SMB
Solutions
Allowlisting
Script Enforcement
Device Control
Patch Management
Remote Tools
Integrations
Server Security
Learn More
Resellers
Affiliates
Resources
Case Studies
For Federal
Partner Programs
Managed Service Providers
Channel Partners
Affiliate Partners
Resource Center
All Resources
Case Studies
Data Sheets
User Guides
White Papers
Blog Resources
PC Matic Blog
Business Security
Home Security
Cyber News
Scam Alerts
Customer Service
Home Support
Business Support
Learn More
Getting Started
Knowledgebase
Tech Support Scams
Fake Virus Scams
The Cyber Scam Report
Town Hall Sessions
Tools & More
Password Generator
Internet Speed Test
What Is My IP?
PC Matic
About
Careers
Learn More
Industry Recognition
Leadership
Commercials
Stay Up-to-Date
Newsroom
Blog
Events
TechTalk Podcast
Home Customers
My Account
PC Matic App
Add a Device
Renew Subscription
Business Customers
Business Login
Business Support
Skip to content
  • Blog
  • Categories
    • Home Security
    • Business Security
    • How To
    • CyberSafe Tips & Tricks
    • CyberNews
    • Scam Alert
  • Inside PC Matic
    • Inside PC Matic
    • Awards & Recognition
    • Press Releases
    • Product Updates
  • Blog
  • Categories
    • Home Security
    • Business Security
    • How To
    • CyberSafe Tips & Tricks
    • CyberNews
    • Scam Alert
  • Inside PC Matic
    • Inside PC Matic
    • Awards & Recognition
    • Press Releases
    • Product Updates
Search
  • Language
    • English
    • Portuguese (BR)
  • Language
    • English
    • Portuguese (BR)

Ask Leo: Does the browser store passwords in cookies?

  • January 10, 2011
  • Leo Notenboom

askleo

By Leo Notenboom

Do IE browser cookies store my password? For example, if someone once logged into my webmail account and saved the cookie on his computer. Will he still be able to access the account using the old cookie if I later changed my password?

It’s time again for one of my most common answers: it depends.

It depends, mostly, on what webmail service you’re using.

Regardless, you may very well be at risk – not only for web mail, but any account that requires you to login.

First let’s be clear about something – it’s the web site you’re visiting that determines what is and is not saved in cookies. IE
actually has nothing to do with the decision, other than providing the mechanisms to store and retrieve cookies.

Since it’s the websites decision, the answer of exactly what gets stored in a cookie will vary dramatically from site to site.
Each will probably save something very different than all the others.

In general, the strictest answer to your question is no, websites do not actually store your password in the cookies that they
place on your machine. That would be fairly poor security, as then anyone with access to your machine could examine the contents of
the cookies and retrieve your password. I’m sure it’s been done, but most of the commercial services have hopefully moved to more
secure approaches.

At a minimum, the password is hashed or encrypted, meaning that the cookie makes sense only to the service in question, and can’t be deciphered. Better yet, the cookies might contain some other kind of data not related to your password at all, but related to
information contained on the service’s computer. For example, the cookie might contain the number 12, and then the service can look
up in its table of currently logged in users entry number 12 and determine if you’re logged in, how long you’ve been active, and
whatever else they need to know to provide their functionality.

But you may still be at risk.

The information that’s kept in cookies or wherever is used to keep you logged in – so that you don’t have to login to see every
page, every message, every click in your webmail program. Even if you browse to a different site when you return it’ll probably
remember that you’re logged in for a while.

Article continued here

FaceBook URL: Leo’s Facebook

Twitter URL: http://twitter.com/askleo

Stop Responding to Threats.
Prevent Them.

Get Protected

Want to get monthly tips & tricks?

Subscribe to our newsletter to get cybersecurity tips & tricks and stay up to date with the constantly evolving world of cybersecurity.

Related Articles

What Your Backup Isn’t For

Understanding the limitations of image backup.

Read More
November 23, 2015

Why You Must Test Your Backup

Don’t miss this critical step in creating a reliable backup.

Read More
November 17, 2015

Fixing Browser Problems

Common troubleshooting steps for solving browser problems.

Read More
October 27, 2015
For Home PC Matic Home Security Support Unlimited
For Business PC Matic Pro PC Matic MSP
Support Home Support Business Support
Partner Programs Become a Partner Affiliates
Company About Careers Industry Recognition Newsroom Blog
Sign-Up For Our Newsletter

© PC Matic, Inc.
All Rights Reserved.

PC Matic, Inc. BBB Business Review
Choose Region
United States Brazil
EULA Privacy Policy Terms & Conditions PC Matic Pro EULA PC Matic Pro Privacy Policy