Phishing attacks have not lost their effectiveness even these days of advanced browsers and increased security measures. Fake pages are increasingly detailed, causing a large number of users to fall into the trap. In an attempt to avoid this problem, Google released the Password Alert extension compatible with Chrome, which warns when the password of our Google account is exposed elsewhere.
Password reuse is technically a security problem. While it is possible for the user to get away with it by being very careful, all it takes is a failure in the weakest link of the chain for the password to end up free in the digital jungle. From there, an attacker's job is reduced to trying it on different services, and that is when breaches get out of control at a chilling speed, especially if the password belongs to a high-profile account, such as Google's email. We recently talked about the risk of saving passwords in an email, but this time, the Mountain View giant itself has decided to add extra protection with the Password Alert extension.
Password Alert does not offer any kind of configuration or advanced menu. In fact, it works silently in the background, monitoring the sites where the user enters their Google password. As long as the destination is accounts.google.com, Password Alert will stay out of the situation, but if the address is different, or has other details indicating a phishing attack, Password Alert will warn that the password has been exposed and recommend its immediate replacement. How can Password Alert know this? Basically, the extension stores a copy of the password protected with a hash and makes comparisons from there. It is a very big responsibility for Password Alert, so we expect good security discipline from Google.
The most important criticism is that Password Alert offers a function that should already be part of not only Chrome, but all browsers. If the only way to improve a browser's security is to resort to extensions, we are facing a clear sign that the development process has cracks in the armor. At the same time, many users have said in the comments that two-step verification is a more robust solution. Password Alert is a legitimate extension, but as always happens in these cases, you have the final word.