Chrome's insane password security strategy
blog.elliottkember.com
Chrome's insane password security strategy
1–10 of 315 posts
Re: Chrome's insane password security strategy
#2Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy.
When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting you to Allow, Deny or Allow Always.
If you click deny, obviously it can't read the keychain entry. But if you click either Allow, or Allow Always the same thing happens: Chrome creates a NEW Keychain entry with the same credentials, location etc, and set to always allow chrome to access it.
What a fucking surprise Google just does what the fuck they want with no regard for what the user has indicated they want.
I'll wait for the Google apologists to tell me it's either a) nothing to worry about or b) a harmless mistake.
Re: Chrome's insane password security strategy
#3Re: Chrome's insane password security strategy
#4I just did a little digging just by visiting some sites I've saved passwords for (in Safari) using Chrome. Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy. When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting…
https://code.google.com/p/chromium/ or Tools > Report an issue...
Re: Chrome's insane password security strategy
#5Re: Chrome's insane password security strategy
#6Re: Chrome's insane password security strategy
#7Re: Chrome's insane password security strategy
#8Re: Chrome's insane password security strategy
#9I just did a little digging just by visiting some sites I've saved passwords for (in Safari) using Chrome. Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy. When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting…
This probably is a mistake, far from harmless, but wouldn't it be better to point it out to the Chrome team and try to get it fixed. Have you logged a bug? https://code.google.com/p/chromium/ or Tools > Report an issue...
Re: Chrome's insane password security strategy
#10(I realise I could visit sites and use password reset, but this is so frictionless as to be insane)