Storing online account passwords in convenient but insecure locations could make personal data vulnerable, according to advice from Which? Tech Support experts. Common practices such as saving login details in a phone's notes app, email, or a document on a computer are discouraged.
If a device is lost, stolen, or hacked, these shortcuts could provide easier access to accounts. Which? highlights specific storage methods to avoid, including unencrypted USB sticks, unprotected notes on smartphones, shared cloud storage folders, and plain text documents on computers.
For instance, an unencrypted USB drive, if lost or stolen, allows anyone who plugs it in to view its files, potentially exposing passwords for email, banking, or shopping accounts. Similarly, while some phone note apps allow locking individual notes, they are not primarily designed for password management. Shared cloud storage folders can also inadvertently expose password documents if sharing settings are not carefully managed or old links remain active.
Saving passwords in plain text files on a computer is also not recommended, as these files can be easily found and read if the computer is compromised.