Live data from Hacker News

Save password on chrome? Think again chrome://chrome/settings/passwords

james-singh.com

11–20 of 27 posts

Re: Save password on chrome? Think again chrome://chrome/settings/passwords

#11
post #3

This is true of Firefox and (possibly?) IE as well, though IE doesn't have an option to show the passwords in the UI. If a user has access to your desktop, then it really doesn't matter if your saved passwords are stored in plain text, you've already lost. And what's the alternative? Ask for a "master" password every time Chrome wants to auto-complete a password for you? That's what extensions like lastpass do, but I…

right, just a hint, for password managing in firefox I use LastPass, it encrypt and autocomplete all.

Re: Save password on chrome? Think again chrome://chrome/settings/passwords

#13
post #3

This is true of Firefox and (possibly?) IE as well, though IE doesn't have an option to show the passwords in the UI. If a user has access to your desktop, then it really doesn't matter if your saved passwords are stored in plain text, you've already lost. And what's the alternative? Ask for a "master" password every time Chrome wants to auto-complete a password for you? That's what extensions like lastpass do, but I…

>"That's what extensions like lastpass do, but I don't think it makes sense for that to be the default."

LastPass keeps you logged in to your "vault" either while the browser remains open, or by time limit. So you're really only entering the master password once per session. I think Firefox has a similar feature; you enter a master password the first time you try to access your passwords.

People not using features like this, at the very the least, is pretty sad. LastPass saved my sanity.

Re: Save password on chrome? Think again chrome://chrome/settings/passwords

#14

What do you think it should do instead? There is no way for it to encrypt the passwords without having to ask you to enter a master password each time it starts. You could argue that it shouldn't let you see them through the user interface, but I would argue that this would be useless - security through obscurity.

I agree with this. The entire promise of password auto-save is to save the user TIME. If the browser locked itself every couple of minutes and asked for a master password between visits, it would not help the user save TIME.

I think the author is confusing a feature exclusively created for convenience with one that would be targeting security exclusively.

PS: However, what better way to get HN traffic than a sensational title like that...

Re: Save password on chrome? Think again chrome://chrome/settings/passwords

#15
This problem has been mitigated in OS X with Keychain, Gnome with Keyring and KDE with Kwallet. If there would be a standard application like that for passwords in Windows it would probably make it easier for most users to keep their passwords from being so easily accessible in cleartext (and I know there are a lot of 3rd party options available, but only power users tend to install those).

Re: Save password on chrome? Think again chrome://chrome/settings/passwords

#17

This is the main problem with Chrome for me at the moment. How hard can it be to add a master password prompt before showing the passwords? Or even to only store them encrypted? I know they wouldn't really be safe even if encrypted, but I just want them not to be available to any random person that has access to my computer for 3 minutes...

If you want to store them encrypted, then chrome has to ask your master password every time you want to actually use the stored passwords (i.e., open a random website). If you don't store them encrypted - then your passwords (as well as everythin else) are available to any random person who has access to your computer for 3 minutes, and not showing them directly is just a minor inconvenience.

Actually, the solution is simple - don't have random persons access your computer for 3 minutes; always locking your screen when leaving is the simple and effective way to counter this risk and many others.

Re: Save password on chrome? Think again chrome://chrome/settings/passwords

#19
post #14

What do you think it should do instead? There is no way for it to encrypt the passwords without having to ask you to enter a master password each time it starts. You could argue that it shouldn't let you see them through the user interface, but I would argue that this would be useless - security through obscurity.

I agree with this. The entire promise of password auto-save is to save the user TIME. If the browser locked itself every couple of minutes and asked for a master password between visits, it would not help the user save TIME. I think the author is confusing a feature exclusively created for convenience with one that would be targeting security exclusively. PS: However, what better way to get HN traffic than a sensatio…

it could for example use the system keychain on MacOS and not expose an interface. Chrome could then read the passwords from the keychain, but any user-access to the password would have to go through "keychain access" and require the users logon password to show in plain. Storage would also be encrypted, so it wouldn't be "security through obscurity" but rather a real step towards protected password storage.

Re: Save password on chrome? Think again chrome://chrome/settings/passwords

#20
post #10

Don't save your passwords in the browser. Instead save them in a password manager such as Password Gorilla: https://github.com/zdia/gorilla/wiki This way, your passwords become "browser independent". You can switch browsers at will, but still have all your passwords in the same place.

I used Password Gorilla for a long time and it's ok.

But I like KeePassX better. Mostly because Gorilla can be absurdly slow sometimes.

Post reply on HN