Lomenett vs. Letting Chrome Save It

Is it safe to save passwords in Chrome? The honest answer is that it's better than reusing one password everywhere, and it's the weakest option the day something bad gets onto your computer. That's the whole page in one sentence, and the rest is the detail, plus what we'd do instead.

First, some credit. If clicking "Save" in your browser is the only password system you've ever had, you're ahead of most people, but keep reading anyway.

What the browser genuinely does well

  • It's free. That's hard to argue with.
  • It's automatic. You never had to set it up, because it started asking one day and you said yes.
  • It syncs. Save a password on your laptop and it's on your phone. That's real convenience, and we won't pretend it isn't.
  • It only fills passwords on the real site. This one matters more than people realize. A scam page can look exactly like your bank's login and fool your eyes, but it can't fool the browser, because the browser checks the actual web address before it fills anything. If the password box stays empty on a page that looks right, that's the browser quietly protecting you. This stops a real amount of phishing, and no offline device does it, ours included.

So what's the problem?

All of your saved passwords live in one stored database on your computer, and there is an entire category of malware built to grab that exact database. Security people call it infostealer malware, and it plays out like this: one bad download, such as a fake installer, a "free" version of a paid program, or an attachment that wasn't what it said it was, runs for a few seconds, copies every saved password out of the browser, sends the whole pile to a criminal, and often deletes itself. You notice nothing at the time, and weeks later your accounts start acting strange.

This is not a rare attack, because it operates at industrial scale. Security researchers have counted billions of stolen passwords circulating from these tools, harvested from millions of infected computers, and browser password stores are their number one target. Google knows it and keeps adding stronger locks, including a major new one in Chrome in 2024, and malware makers broke it within months and have kept breaking each new version since. That's not because Google is careless. It's because the browser and the malware are running on the same machine, and the malware only has to win once.

One more catch: your passwords live in an account

Chrome's passwords are tied to your Google account, Edge's to Microsoft, and Safari's to Apple. If you get locked out of that account, or decide to leave it, your passwords are part of the negotiation, and they only really work smoothly in that one browser. We think your passwords shouldn't be tied to any one company at all.

If you stick with the browser, do these two things

Neither requires a purchase, and we'd rather you be safer either way. First, turn on your browser's extra password encryption if it offers it (Chrome calls it on-device encryption, and Safari's iCloud Keychain already encrypts end to end). Second, be careful about downloads, because almost every infostealer infection starts with someone installing something they shouldn't have.

Where a password typer fits

A password typer keeps your passwords off the computer entirely. Lomenett is ours, an aluminum USB stick with a little screen and a thumbwheel. You pick a login, plug it in, and it types the password like a keyboard, with no app, no account, and no cloud. Your passwords aren't stored on your computer, so there is no password database for malware to grab, and one bad download can't hand over all of them at once, because all of them were never there.

In full honesty, because that's the house rule: if your computer is already infected, malware can still capture a password as it's typed, and that's true of every password manager ever made, including ours. Lomenett also types wherever your cursor is and doesn't check the web address the way the browser does, so glancing at the address bar is back on you, and the browser wins that point. Lomenett also costs $90 once while the browser is free forever, and we're not going to pretend that's nothing.

Browser (Chrome, Edge, Safari)Lomenett
PriceFree$90, one time
EffortNone, it's automaticPlug in, scroll, click
Syncs between devicesYesNo. One stick, works on any computer or most phones you plug it into
Checks you're on the real siteYes, and it stops some phishingNo, you check the address bar
Malware steals your whole password listIts favorite targetThe list isn't on the computer
Tied to a company accountYes (Google, Microsoft, or Apple)No account at all

If you want the deeper comparisons, we've written them: Lomenett vs. cloud password managers for apps like 1Password and Bitwarden, Lomenett vs. KeePass and DIY builds for the do-it-yourself crowd, and why a short PIN is safe on Lomenett if you're wondering how a little stick protects itself.