Google’s new Chrome extension squeals on compromised passwords

Today is Safer Internet Day, so it's fitting that Google chose this morning to release its Password Checkup extension for Chrome.

Just as it sounds, the Password Checkup extension audits your username and password when logging into a website. If the combination is known to be compromised, you'll see a big red warning, as shown in the image above.

"We want to help you stay safe not just on Google, but elsewhere on the web as well. This is where the new Password Checkup Chrome extension can help. Whenever you sign in to a site, Password Checkup will trigger a warning if the username and password you use is one of over 4 billion credentials that Google knows to be unsafe," Google explains.

Google jointed developed the extension with cryptography experts at Stanford University. While your information is sent to Google, the company claims it has no way of actually seeing your login information. That's because the extension uses "multiple rounds of hashing, k-anonymity, private information retrieval, and a technique called blinding. This infographic breaks it down into more detail.

Password Checkup is a first-party extension, which begs the question as to why Google doesn't just bake into Chrome natively, and make it opt-in. That might the direction it takes. For now, though, Google views it as an "early experiment."

The extension arrives on the heels of largest compromised data dumps to date, known as Collection #1 and Collection #2-5. These collections are essentially roundups of previously stolen credentials. The first one contains over 770 million email addresses and 21 million passwords, while the second batch exposes 2.2 billion unique usernames and passwords.

I've only been using the Password Checkup a short while, but so far I haven't noticed any side effects. If you want to give it a whirl yourself, follow this link. You should also consider a password manager.

TOPICS
Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Browsers
Google campus sign
Google asks Trump's DOJ to please, please, please reconsider parting it from Chrome
ANKARA, TURKIYE - SEPTEMBER 06: In this photo illustration, Chrome logo is being displayed on a mobile phone screen in front of computer screen in Ankara, Turkiye on September 06, 2023.
uBlock and a handful of other popular Google Chrome extensions have been axed overnight, but some of them just require turning off and on again
Opera GX, Opera's gaming browser
Morbid curiosity made me swap from Chrome to Opera's 'gaming browser' but its early 2000s custom ringtone vibes give me the ick
The Opera Air 'mindfulness browser' on top of a blurred background
Opera has unveiled 'the world’s first browser with mindfulness at its core' and, to my surprise, I might be convinced
MOUNTAIN VIEW, CALIFORNIA - AUGUST 22: A view of Google Headquarters in Mountain View, California, United States on August 22, 2024.
Google being pushed to sell off Chrome is likely a good thing, but don't cheer on the decision just yet
Chrome Browser Logos
Google has changed its mind about dropping support for third-party cookies in Chrome, after years of trying to make it happen
Latest in News
Napster client circa 1999
Former music-pirating platform Napster to be reborn rather ironically as a metaverse for musicians to connect with their fans after $207 million deal
The snazzy red and black HyperX Cloud Alpha wireless headphones float in a teal void. The microphone is attached to the headset.
The best wireless gaming headset is now even better in the Amazon Big Spring Sale, boasting a more than $50 discount
A chip being held up in an Intel fab
Intel is reportedly 'working to finalize commitments from Nvidia' as a foundry partner, suggesting gaming potential for the 18A node
Amazon box
Don't panic! The 'Do Not Send Voice Recordings' option Amazon just removed was only used by 0.03% of customers and they can still have it
Digital generated image of people surrounded by interactive transparent and glowing panels with data. Visualising smart technology, blockchain and artificial intelligence
Now I shall demand the cookies! Proposed new browsing agreement turns the tables and lets users dictate terms to websites
Intel CEO, Pat Gelsinger, with a 18A SRAM test wafer
Former Intel CEO, Pat Gelsinger becomes executive chairman of a 'Technology Platform Connecting the Faith Ecosystem' to work on Christian AI using DeepSeek