Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

1–10 of 315 posts

Re: Chrome's insane password security strategy

#2
I just did a little digging just by visiting some sites I've saved passwords for (in Safari) using Chrome.

Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy.

When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting you to Allow, Deny or Allow Always.

If you click deny, obviously it can't read the keychain entry. But if you click either Allow, or Allow Always the same thing happens: Chrome creates a NEW Keychain entry with the same credentials, location etc, and set to always allow chrome to access it.

What a fucking surprise Google just does what the fuck they want with no regard for what the user has indicated they want.

I'll wait for the Google apologists to tell me it's either a) nothing to worry about or b) a harmless mistake.

Re: Chrome's insane password security strategy

#4
post #2

I just did a little digging just by visiting some sites I've saved passwords for (in Safari) using Chrome. Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy. When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting…

This probably is a mistake, far from harmless, but wouldn't it be better to point it out to the Chrome team and try to get it fixed. Have you logged a bug?

https://code.google.com/p/chromium/ or Tools > Report an issue...

Re: Chrome's insane password security strategy

#7
No, no, no, no, NO! What do you think "store password" means, when you click it? If you can fire up your browser and log in without ever typing in a password how could you EVER assume your passwords are stored in anything but plaintext? I'm sorry, this article just shows stupidity of the user rather than "Chrome’s insane password security strategy".

Re: Chrome's insane password security strategy

#8
I did "Reset Safari..." once, and it wiped all my Chrome passwords. Guess they're all stored in the Keychain! But the wording on both Safari's and Chrome's end isn't helpful. "Reset Safari" shouldn't mean "Reset your Keychain", and "Do you want Google Chrome to save you password" should probably be reworded to "Do you want to save your password in the OS X Keychain". :(

Re: Chrome's insane password security strategy

#9
post #2

I just did a little digging just by visiting some sites I've saved passwords for (in Safari) using Chrome. Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy. When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting…

This probably is a mistake, far from harmless, but wouldn't it be better to point it out to the Chrome team and try to get it fixed. Have you logged a bug? https://code.google.com/p/chromium/ or Tools > Report an issue...

A mistake..? So they accidentally wrote code to copy your credentials and create a new keychain item which Chrome has permanent access to?

Re: Chrome's insane password security strategy

#10
To those saying this isn't insane... you are wrong. I can open anyone's chrome browser and access their passwords without a master password? That's plain fucked up.

(I realise I could visit sites and use password reset, but this is so frictionless as to be insane)

Post reply on HN