Your sync account holds your bookmarks and passwords, so it is worth two minutes of protection: enable two-factor authentication, review the device list periodically and turn on unusual location alerts.
What to do first
Use a strong, unique password, enable two-factor authentication, and review and remove devices you no longer use in the account center.
- A strong unique password
- Two-factor authentication
- Periodic cleanup of signed-in devices
- Unusual location alerts
Protecting the passwords themselves
Passwords stored in the browser are encrypted and require system identity verification to view. Check reused and breached password alerts regularly and change them.
- Viewing plain text requires system verification
- Reused passwords are flagged
- Breach comparison runs locally
- Export requires a second confirmation
If something looks wrong
Change the password immediately, remove suspicious devices from the device list, sign in again on your own devices, and pause sync while you investigate if needed.
- Change the account password at once
- Sign suspicious devices out remotely
- Sign in again on your own devices
- Check whether bookmarks or passwords were altered
FAQ
I lost the phone used for two-factor authentication — what now?
Use the saved backup codes or the recovery email; if neither works, go through the account recovery process to verify your identity.
Can I export passwords as a backup?
Yes, as a CSV file, but it is plain text and unprotected — store it carefully and delete it once migration is done.