{"id":11684,"date":"2023-09-04T12:47:52","date_gmt":"2023-09-04T09:47:52","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=11684"},"modified":"2023-09-04T12:47:52","modified_gmt":"2023-09-04T09:47:52","slug":"how-to-store-passwords-securely","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/how-to-store-passwords-securely\/11684\/","title":{"rendered":"Parolalar g\u00fcvenli bir \u015fekilde nas\u0131l saklan\u0131r?"},"content":{"rendered":"<p>Taray\u0131c\u0131da saklamak, sizi her seferinde parolalar\u0131 yeniden girme zahmetinden kurtar\u0131r, bu da size ger\u00e7ek anlamda zaman kazand\u0131r\u0131r. Ama bu ne kadar g\u00fcvenlidir? Bu yaz\u0131da, parolalar\u0131 taray\u0131c\u0131n\u0131zda saklamaman\u0131z i\u00e7in \u00fc\u00e7 neden ve neden \u00e7ok daha g\u00fcvenli bir saklama y\u00f6ntemi, yani bir parola y\u00f6neticisi kullanman\u0131z gerekti\u011fi a\u00e7\u0131klan\u0131yor.<\/p>\n<h2>1. Parola h\u0131rs\u0131zlar\u0131<\/h2>\n<p>Parolalar\u0131n taray\u0131c\u0131larda saklanmas\u0131yla ilgili temel sorun, kullan\u0131labilirlik ad\u0131na g\u00fcvenlikten \u00f6d\u00fcn verilmesidir. Bu durum en az\u0131ndan en pop\u00fcler \u00fc\u00e7 taray\u0131c\u0131 i\u00e7in ge\u00e7erlidir: Google Chrome, Mozilla Firefox ve Microsoft Edge. Bu taray\u0131c\u0131lar kullan\u0131c\u0131 parolalar\u0131n\u0131 son derece g\u00fcvensiz bir \u015fekilde saklar.<\/p>\n<p>Bunun nedeni, t\u00fcm taray\u0131c\u0131lar\u0131n parolalar\u0131 \u00e7ok tahmin edilebilir bir yerde, yolu kimse i\u00e7in gizli olmayan bir klas\u00f6rde saklamas\u0131d\u0131r. Parolalar\u0131n kendileri \u015fifrelenmi\u015f olsa da, \u015fifreleme anahtar\u0131 da onlara yak\u0131n bir yerde saklan\u0131r ve kolayca eri\u015filebilir durumdad\u0131r. Bu anahtar\u0131 ele ge\u00e7iren bir sald\u0131rgan parolalar\u0131 \u00e7\u00f6zebilir ve \u00e7alabilir. Komik bir durum: kap\u0131 g\u00fcvenli bir \u015fekilde kilitlenmi\u015f gibi g\u00f6r\u00fcn\u00fcyor ama anahtar paspas\u0131n alt\u0131nda ve t\u00fcm d\u00fcnya bunu biliyor.<\/p>\n<p>Asl\u0131nda, taray\u0131c\u0131lar bu durumu birbirleriyle rekabet etmek i\u00e7in kullan\u0131yor: kullan\u0131c\u0131lar\u0131n ge\u00e7i\u015fini kolayla\u015ft\u0131rmak i\u00e7in, genellikle saklanan parolalar da d\u00e2hil olmak \u00fczere eski taray\u0131c\u0131dan t\u00fcm kay\u0131tl\u0131 verileri i\u00e7e aktarmay\u0131 teklif ediyorlar.<\/p>\n<p>Bu \u00f6zelli\u011fi ba\u015fka kimlerin kulland\u0131\u011f\u0131n\u0131 tahmin edebiliyor musunuz? Cevap do\u011fru. Kimlik bilgilerini \u00e7almak i\u00e7in tasarlanm\u0131\u015f b\u00fct\u00fcn bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar vard\u0131r ve bunlar genellikle <a target=\"_blank\" href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/trojan-psw-psw-password-stealing-ware\/\" rel=\"noopener\">parola h\u0131rs\u0131zlar\u0131<\/a> olarak adland\u0131r\u0131l\u0131r. Bu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar, taray\u0131c\u0131da saklanan parolalar\u0131 i\u00e7erdi\u011fi bilinen klas\u00f6rleri tarar, paspas\u0131n alt\u0131ndaki anahtar\u0131 bulur, ard\u0131ndan parolalar\u0131n \u015fifresini \u00e7\u00f6zer ve ganimeti siber su\u00e7lular\u0131n sunucular\u0131na y\u00fckler. Daha sonra bu parolalar genellikle bir veritaban\u0131na kaydedilir ve hesaplar\u0131 ele ge\u00e7irmek i\u00e7in bunlar\u0131 kullanan di\u011fer doland\u0131r\u0131c\u0131lara karanl\u0131k a\u011f \u00fczerinden toplu olarak sat\u0131l\u0131r (siber su\u00e7 d\u00fcnyas\u0131nda dar uzmanla\u015fma uzun zamand\u0131r bir normdur).<\/p>\n<p>Bir taray\u0131c\u0131da saklanan parolalar\u0131 \u00e7alman\u0131n ne kadar kolay oldu\u011funu anlamak i\u00e7in, bir Python beti\u011finden ba\u015fka bir \u015fey kullanmadan <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/fractionalciso.com\/browser-password-managers-flawed-security-by-design\/\">Chrome, Firefox ve Edge\u2019den parolalar\u0131n nas\u0131l h\u0131zl\u0131 bir \u015fekilde \u00e7\u0131kar\u0131laca\u011f\u0131n\u0131<\/a> a\u00e7\u0131k\u00e7a g\u00f6steren bir videoyu izlemenizi \u00f6neririz.<\/p>\n<div id=\"attachment_11686\" style=\"width: 1362px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2023\/09\/04124405\/why-it-is-not-safe-to-store-passwords-in-browsers-01.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-11686\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2023\/09\/04124405\/why-it-is-not-safe-to-store-passwords-in-browsers-01.jpg\" alt=\"Google Chrome, Mozilla Firefox ve Microsoft Edge'den parolalar\u0131 \u00e7\u0131karma\" width=\"1352\" height=\"725\" class=\"size-full wp-image-11686\"><\/a><p id=\"caption-attachment-11686\" class=\"wp-caption-text\">Google Chrome, Mozilla Firefox ve Microsoft Edge\u2019de depolanan parolalar\u0131n nas\u0131l \u00e7\u0131kar\u0131laca\u011f\u0131n\u0131n g\u00f6sterimi. <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/fractionalciso.com\/browser-password-managers-flawed-security-by-design\/\">(Kaynak)<\/a><\/p><\/div>\n<h2>2. Bilgisayara fiziksel eri\u015fim<\/h2>\n<p>Bu t\u00fcr yaramazl\u0131klar\u0131 sadece \u00f6zel olarak e\u011fitilmi\u015f k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar de\u011fil, bilgisayar\u0131n\u0131za fiziksel eri\u015fimi olan herkes yapabilir. \u00dcstelik bunun i\u00e7in ileri d\u00fczey bilgisayar korsanl\u0131\u011f\u0131 becerileri de gerekmez. Taray\u0131c\u0131da Saklanan parolalar\u0131 ele ge\u00e7irmeye yarayan komut dosyalar\u0131 internet \u00fczerinde kolayca bulunabiliyor. Gereken tek \u015fey onlar\u0131 \u00e7al\u0131\u015ft\u0131rmak.<\/p>\n<p>Bilgisayar\u0131n\u0131z\u0131 kilitlemeden \u00f6ylece b\u0131rak\u0131rsan\u0131z, fazla merakl\u0131 bir akraban\u0131z veya i\u015f arkada\u015f\u0131n\u0131z bile bunu yapabilir. Ya da ke\u015fif ama\u00e7l\u0131 olarak ofisinizi ziyaret eden bir bilgisayar korsan\u0131. Temel olarak, herhangi biri. \u00d6nemli olan nokta, taray\u0131c\u0131da saklanan t\u00fcm parolalar\u0131n\u0131z\u0131n potansiyel olarak d\u00fc\u015fman ellere ge\u00e7ecek olmas\u0131d\u0131r.<\/p>\n<p>Davetsiz misafir, taray\u0131c\u0131da kay\u0131tl\u0131 dosyadan parolalar\u0131 \u00e7\u0131karmak i\u00e7in do\u011fru komut dosyas\u0131na sahip olmasa bile, parolalar\u0131n sakland\u0131\u011f\u0131 sitelerin listesi i\u00e7in ayarlar\u0131 tarayabilir ve ard\u0131ndan \u00f6rne\u011fin yaz\u0131\u015fmalar\u0131n\u0131z\u0131 okumak veya hakk\u0131n\u0131zdaki di\u011fer s\u0131rlar\u0131 \u00f6\u011frenmek i\u00e7in bunlardan birine giri\u015f yapabilir.<\/p>\n<p>D\u00fcnyan\u0131n en pop\u00fcler taray\u0131c\u0131s\u0131 bile (bilmiyorsan\u0131z Google Chrome) bu t\u00fcr eylemleri \u00f6nleyecek temel bir mekanizmaya sahip de\u011fil. Firefox geli\u015ftiricileri, kullan\u0131c\u0131lar\u0131n kay\u0131tl\u0131 parolalar\u0131 birincil parola ile korumalar\u0131na izin verecek kadar d\u00fc\u015f\u00fcnceli olsalar da, bu se\u00e7enek varsay\u0131lan olarak devre d\u0131\u015f\u0131 b\u0131rak\u0131lm\u0131\u015f durumda. Birincil parola a\u00e7\u0131k\u00e7a etkinle\u015ftirilmeli ve yap\u0131land\u0131r\u0131lmal\u0131d\u0131r ve bir\u00e7ok Firefox kullan\u0131c\u0131s\u0131n\u0131n bundan haberdar olmas\u0131 bile pek m\u00fcmk\u00fcn de\u011fil.<\/p>\n<h2>3. Taray\u0131c\u0131 hesaplar\u0131n\u0131n ele ge\u00e7irilmesi<\/h2>\n<p>Bu sorun, kullan\u0131c\u0131lara <em>kolayl\u0131k sa\u011flamak<\/em> amac\u0131yla farkl\u0131 cihazlardaki taray\u0131c\u0131lar\u0131 senkronize etmek i\u00e7in bir hesap olu\u015fturma imkan\u0131 sunan t\u00fcm taray\u0131c\u0131larda ortakt\u0131r. Bu, yer imlerinin, taray\u0131c\u0131 oturumlar\u0131n\u0131n, uzant\u0131lar\u0131n, ayarlar\u0131n ve kay\u0131tl\u0131 parolalar\u0131n t\u00fcm\u00fcn\u00fcn senkronize edildi\u011fi ve bulutta depoland\u0131\u011f\u0131 anlam\u0131na gelir. B\u00f6yle bir durumda bir bilgisayar korsan\u0131 taray\u0131c\u0131 hesab\u0131n\u0131za girmeyi ba\u015fard\u0131\u011f\u0131nda, tek yapmas\u0131 gereken ayn\u0131 hesab\u0131 kullanarak ba\u015fka bir bilgisayarda oturum a\u00e7makt\u0131r. Ard\u0131ndan, sosyal a\u011flardan \u00e7evrimi\u00e7i bankalara kadar, parolalar\u0131 taray\u0131c\u0131da saklanan t\u00fcm hesaplar\u0131n\u0131z\u0131 ele ge\u00e7irebilir.<\/p>\n<h2>Parola y\u00f6neticisi neden taray\u0131c\u0131dan iyidir?<\/h2>\n<p>Taray\u0131c\u0131lar gibi <a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a> da kimlik bilgilerinizi hat\u0131rlar ve web sitelerinde oturum a\u00e7arken bunlar\u0131 otomatik olarak doldurman\u0131z\u0131 sa\u011flar. Ancak taray\u0131c\u0131 geli\u015ftiricilerinin aksine, g\u00fcvenlikten \u00f6d\u00fcn vermiyoruz. Parola y\u00f6neticimizde, birincil parola varsay\u0131lan olarak kullan\u0131l\u0131r ve devre d\u0131\u015f\u0131 b\u0131rak\u0131lamaz, b\u00f6ylece <em>t\u00fcm<\/em> kay\u0131tl\u0131 parolalar\u0131n\u0131z <em>her zaman<\/em> koruma alt\u0131nda olur. Dolay\u0131s\u0131yla, birisi bilgisayar\u0131n\u0131za fiziksel eri\u015fim sa\u011flasa bile, y\u00f6neticide depolanan kimlik bilgilerini kullanarak sitelere kolayca giri\u015f yapamayacakt\u0131r. Bunu yapmak i\u00e7in, sizden ba\u015fka kimsenin bilmedi\u011fi (mesela bir ka\u011f\u0131da yaz\u0131p monit\u00f6r\u00fcn\u00fcz\u00fcn kenar\u0131na yap\u0131\u015ft\u0131rmad\u0131\u011f\u0131n\u0131z) birincil parolaya ihtiya\u00e7lar\u0131 olacakt\u0131r.<\/p>\n<p><a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>\u2018\u0131n bir di\u011fer avantaj\u0131 da elbette t\u00fcm parolalar\u0131n yaln\u0131zca \u015fifrelenmi\u015f bi\u00e7imde saklanmas\u0131d\u0131r. Ve en \u00f6nemlisi, \u015fifre \u00e7\u00f6zme anahtar\u0131 \u201cpaspas\u0131n alt\u0131nda\u201d de\u011fil. \u015eifreleme anahtar\u0131, birincil parola temel al\u0131narak an\u0131nda AES-256 algoritmas\u0131 kullan\u0131larak olu\u015fturulur ve b\u00f6ylece onu saklamam\u0131za gerek kalmaz. Hi\u00e7bir yerde. Hi\u00e7bir zaman. B\u00f6ylece bir h\u0131rs\u0131z bilgisayar\u0131n\u0131za girmeyi ba\u015farsa bile hi\u00e7bir \u015fey \u00e7alamaz; t\u00fcm parolalar\u0131n\u0131z g\u00fcvenli bir \u015fekilde \u015fifrelenmi\u015f durumdad\u0131r. Bu arada, <a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>\u2018\u0131 <a href=\"https:\/\/www.kaspersky.com.tr\/premium?icid=tr_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">Kaspersky Premium<\/a>\u2018un bir par\u00e7as\u0131 olarak kullan\u0131rsan\u0131z, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n s\u0131zmas\u0131na bile izin vermeyiz.<\/p>\n<p>Son bir \u015fey. Do\u011fal olarak, cihazlar aras\u0131nda parolalar\u0131 senkronize etmek i\u00e7in bulutu kullan\u0131yoruz \u2013 t\u00fcm parolalar\u0131n\u0131z <a target=\"_blank\" href=\"https:\/\/my.kaspersky.com\/tr\" rel=\"noopener nofollow\">My Kaspersky<\/a> hesab\u0131n\u0131za ba\u011fl\u0131d\u0131r. Ancak bir sald\u0131rgan bir \u015fekilde bu hesaba eri\u015fim sa\u011flasa bile, <a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>\u2018da saklanan parolalar\u0131n\u0131z yine de tamamen g\u00fcvende olacakt\u0131r. Bunun nedeni, bulutta yaln\u0131zca \u015fifrelenmi\u015f bi\u00e7imde saklan\u0131yor olmalar\u0131 ve \u015fifre \u00e7\u00f6zme anahtar\u0131n\u0131n yaln\u0131zca sizin bildi\u011finiz ve sald\u0131rganlar\u0131n hi\u00e7bir \u015fekilde ula\u015famayaca\u011f\u0131 birincil parola temel al\u0131narak olu\u015fturulmas\u0131d\u0131r.<\/p>\n<p>Ayr\u0131ca <a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>\u2018\u0131 yak\u0131n zamanda yeni kullan\u0131c\u0131lar kazanmaya devam eden Opera ve Opera GX taray\u0131c\u0131lar\u0131n\u0131 destekleyecek \u015fekilde g\u00fcncelledik. Bu, art\u0131k en pop\u00fcler taray\u0131c\u0131lar\u0131n t\u00fcm\u00fcn\u00fc destekledi\u011fimiz anlam\u0131na geliyor: Chrome (ve Chromium tabanl\u0131 taray\u0131c\u0131lar), Safari, Firefox, Edge ve Opera.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kpm\">\n","protected":false},"excerpt":{"rendered":"<p>Kimlik bilgileri nerede saklanmal\u0131: taray\u0131c\u0131da m\u0131 parola y\u00f6neticisinde mi? Elbette ikincisi. \u0130\u015fte nedeni.<\/p>\n","protected":false},"author":2747,"featured_media":11685,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1284,1285],"tags":[1624,16,22,744,1105,1520,1525,2007,1749,551],"class_list":{"0":"post-11684","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tips","8":"category-products","9":"tag-2fa","10":"tag-chrome","11":"tag-google","12":"tag-guvenlik","13":"tag-kaspersky-password-manager","14":"tag-parola-yoneticisi","15":"tag-parolalar","16":"tag-sizintilar","17":"tag-tarayicilar","18":"tag-urunler-2"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/how-to-store-passwords-securely\/11684\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/how-to-store-passwords-securely\/26075\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/how-to-store-passwords-securely\/21537\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/how-to-store-passwords-securely\/10950\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/how-to-store-passwords-securely\/28769\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/how-to-store-passwords-securely\/26384\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/how-to-store-passwords-securely\/26631\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/how-to-store-passwords-securely\/29106\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/how-to-store-passwords-securely\/27972\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/how-to-store-passwords-securely\/35876\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/how-to-store-passwords-securely\/48784\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/how-to-store-passwords-securely\/20917\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/how-to-store-passwords-securely\/21696\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/how-to-store-passwords-securely\/30389\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/how-to-store-passwords-securely\/34558\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/how-to-store-passwords-securely\/28882\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/how-to-store-passwords-securely\/26666\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/how-to-store-passwords-securely\/32373\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/how-to-store-passwords-securely\/32042\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/urunler-2\/","name":"\u00fcr\u00fcnler"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2747"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=11684"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11684\/revisions"}],"predecessor-version":[{"id":11688,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11684\/revisions\/11688"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/11685"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=11684"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=11684"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=11684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}