Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

81–90 of 315 posts

Re: Chrome's insane password security strategy

#81
post #78

Earlier quoted context omitted.

But it is a false sense of security. Joe User doesn't know a thing about how this magical box of tricks called a computer works. He just assumes that his data is safe on it, and won't get into the wrong hands, and that his passwords will always be protected by asterisks or what-not. Sure, you may encrypt them using keychain, which is good, and yes, if someone has physical access to their machine and user account then…

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild.

My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords.

It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration.

Re: Chrome's insane password security strategy

#82
post #80

Earlier quoted context omitted.

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

Yes, but by your reasoning, surely obfuscating passwords when inputted into websites is also pointless, yet you do do this in Chrome, which is inconsistent with your reasoning. I know, and you know, that locking one's account is the Thing To Do when not at one's terminal, but Joe User is still learning this, and in practice, most people do not lock their terminals when AFK, leaving them open to others in the househol…

> Yes, but by your reasoning, surely obfuscating passwords when inputted into websites is also pointless, yet you do do this in Chrome, which is inconsistent with your reasoning.

Passwords are normally masked to prevent shoulder surfing, but the presumption is that the correct person is still at the keyboard. When you explicitly chose to show a password, the presumption is that you attempt to be aware of who is around you. If the bad guy is at the keyboard for your unlocked account, the fact is you've already lost.

> Yes, locking the account is the user's responsibility, but it wouldn't hurt to help them out, by not making it possible to view all a user's passwords in their chrome preferences.

This isn't about pushing responsibility off on the user. It's about not tricking users into believing they're safer than they actually are.

> Again, I'm aware that you could simply hop into keychain and check "show password", but this prompts for the user account password. At the very least, you should be doing the same.

If I'm an attacker, why would I use the keychain app to get Safari passwords? Just navigate to the site and change the auto-filled password field to text, or use an extension, or one of the many system-level approaches you have at your disposal. Many of these things are even available as tools that any novice can trivially acquire and use.

Re: Chrome's insane password security strategy

#83

Earlier quoted context omitted.

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

Re: Chrome's insane password security strategy

#84

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this.

What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous.

Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security.

How on earth can I convince you that many, many, many people are surprised and concerned about this? Can I direct them to you on Twitter?

Re: Chrome's insane password security strategy

#85
post #80

Earlier quoted context omitted.

Yes, but by your reasoning, surely obfuscating passwords when inputted into websites is also pointless, yet you do do this in Chrome, which is inconsistent with your reasoning. I know, and you know, that locking one's account is the Thing To Do when not at one's terminal, but Joe User is still learning this, and in practice, most people do not lock their terminals when AFK, leaving them open to others in the househol…

> Yes, but by your reasoning, surely obfuscating passwords when inputted into websites is also pointless, yet you do do this in Chrome, which is inconsistent with your reasoning. Passwords are normally masked to prevent shoulder surfing, but the presumption is that the correct person is still at the keyboard. When you explicitly chose to show a password, the presumption is that you attempt to be aware of who is aroun…

You're still missing the point, and you're scarily out of touch. A novice (I use my mother as my reference novice) has NO IDEA how to go about changing a form field type, but does know how to drill into preferences and look at passwords-on-a-silver-platter.

If you honestly think that the average user knows how to crack, hack and phreak, you're on another planet.

I cannot comprehend what useful purpose showing the passwords achieves. This falls into the same bucket as eCommerce sites which email the user their password after they sign up. In fact, again, by your measure, why do other google products not display passwords in plaintext? For instance, gmail?

I also note you sidestepped the suggestion of enforcing access control before allowing a user to view these passwords - it wouldn't be painful to implement, and would to a large degree obviate the issue.

Re: Chrome's insane password security strategy

#86

Earlier quoted context omitted.

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've already surrendered any pretense of security. Effectively, you're asking that we lull our users into a false sense of security.

I've enumerated this multiple times now, so I'm not sure how else to explain it. The simple fact is that you need to lock your user account if you want to protect your information. If you don't do that, nothing else really matters because it's all just theater and won't actually stop anyone willing to invest minimal effort.

Re: Chrome's insane password security strategy

#87

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

You're right, locking the operating system will secure it. But people aren't doing that. And people lend their computers to friends sometimes. It happens. I think the actual situation is that you don't understand how people are using computers, and how people expect them to behave - which is very important.

Your software allows me to open up one application and see all passwords. It's likely the single most-used application, and the easiest attack vector on the machine. If I wanted your password, I'd try Chrome first. It's very widely-used, and therefore a huge vector. That is the problem here.

Either change it, or better communicate the need to lock your system. Because to an average user on the street, this is a scary thing to be able to do so easily.

Is there a public point of contact that I can speak to about this?

Re: Chrome's insane password security strategy

#88
post #20
post #16

Shock! Firefox is insafe too! Call the presses, write the blogs! Go to any page where browser (Chrome or Firefox) pre-fills password. Click on the password, click on "inspect element", change the type of the form input from "password" to, say, "pasword". You just broke the internet security.

Firefox does have a master password.

Oh.

That is, actually, pretty nice.

Re: Chrome's insane password security strategy

#89
post #85

Earlier quoted context omitted.

> Yes, but by your reasoning, surely obfuscating passwords when inputted into websites is also pointless, yet you do do this in Chrome, which is inconsistent with your reasoning. Passwords are normally masked to prevent shoulder surfing, but the presumption is that the correct person is still at the keyboard. When you explicitly chose to show a password, the presumption is that you attempt to be aware of who is aroun…

You're still missing the point, and you're scarily out of touch. A novice (I use my mother as my reference novice) has NO IDEA how to go about changing a form field type, but does know how to drill into preferences and look at passwords-on-a-silver-platter. If you honestly think that the average user knows how to crack, hack and phreak, you're on another planet. I cannot comprehend what useful purpose showing the pas…

I'm sorry, but I really do understand your argument. You're claiming that the same novice who can't install a simple application or or follow three steps to reveal a password on the page will be capable of drilling down through the Chrome settings menus and displaying passwords. The corollary to your claim is that the threat of this novice outweighs the damage of encouraging people to leave their computers unlocked in a potentially hostile environment.

Drawing equivalence to sites that email your password is also misguided. The issue with those sites is that, contrary to a password manager, they have no reason to ever retain the cleartext password. And more fundamentally, there's no excuse to ever transmit credentials in the clear over a network. Whereas in this case, we're talking about showing the user passwords that must be retained in a recoverable form, displaying only on user request, and within a security context that can trivially access them anyway.

At this point I think I've repeatedly conveyed the reasons for Chrome's design decisions on this front. Since there's no new information, and the discussion seems to be going around in circles, I don't really see a value in continuing this thread.

Re: Chrome's insane password security strategy

#90

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

I don't think that saying if someone has access to your computer then you're screwed anyway is really an excuse.

You talk about lulling users into a false sense of security but do you have any idea how many Chrome users assume that their saved passwords can't just be viewed in plain text with a couple of clicks? I had no idea until I read Elliott's article and I immediately turned the feature off and deleted all my saved passwords.

Post reply on HN