Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

91–100 of 315 posts

Re: Chrome's insane password security strategy

#91

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

justin: other applications offer an added layer of security through a master password, which chrome does not, are you saying that this has 0 affect of the level of security surrounding the stored passwords?

Or are you saying chrome(ium?) uses the same technique but hidden to the user?

Re: Chrome's insane password security strategy

#92

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

You're right, locking the operating system will secure it. But people aren't doing that. And people lend their computers to friends sometimes. It happens. I think the actual situation is that you don't understand how people are using computers, and how people expect them to behave - which is very important. Your software allows me to open up one application and see all passwords. It's likely the single most-used appl…

Elliottkmember is right here. Chrome's approach to this is absurd. What if you simply don't want friends, coworkers, significant others browsing your passwords? At least tell users that if they choose to save passwords in Chrome, that everyone who uses their computer, even pretty non-technical people, will be able to access those passwords. Tell them that storing their passwords in Chrome is unsafe.

Justin, can you tell us the real reason Chrome does it this way? Because the reasons you list so far don't make sense.

Re: Chrome's insane password security strategy

#93
post #90

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

I don't think that saying if someone has access to your computer then you're screwed anyway is really an excuse. You talk about lulling users into a false sense of security but do you have any idea how many Chrome users assume that their saved passwords can't just be viewed in plain text with a couple of clicks? I had no idea until I read Elliott's article and I immediately turned the feature off and deleted all my s…

If a technical person with a bit of knowledge and a few minutes has access to your computer then yes, you're a bit screwed.

If the broadband engineer comes round to investigate your connectivity issues and you (sensibly) watch over their shoulder while they fiddle with your browser settings, looking away for 10 seconds shouldn't result in them having ALL your passwords.

It's about ease & simplicity of breaching the "security" for non-technical people as well as techies.

Re: Chrome's insane password security strategy

#94

Earlier quoted context omitted.

It's especially insane on OSX which already has an OS-wide and ~secure (more secure than this anyway) password manager: Keychain.

Note that Chrome is using keychain and that you can dump the complete keychain data with all passwords decrypted via terminal anyway. You don't need any third party software ala Chrome installed. E.g.: security find-internet-password -g -s news.ycombinator.com Klick allow and that's it. The master password question for showing individual passwords in the Keychain.app does not protect your passwords. As others said: d…

You're right, and this is really bad. The thing Chrome gives you on top of this is greater discoverability - i.e. a list of ALL passwords - and a few buttons to make it easier for non-technical users.

Re: Chrome's insane password security strategy

#95
post #85

Earlier quoted context omitted.

You're still missing the point, and you're scarily out of touch. A novice (I use my mother as my reference novice) has NO IDEA how to go about changing a form field type, but does know how to drill into preferences and look at passwords-on-a-silver-platter. If you honestly think that the average user knows how to crack, hack and phreak, you're on another planet. I cannot comprehend what useful purpose showing the pas…

I'm sorry, but I really do understand your argument. You're claiming that the same novice who can't install a simple application or or follow three steps to reveal a password on the page will be capable of drilling down through the Chrome settings menus and displaying passwords. The corollary to your claim is that the threat of this novice outweighs the damage of encouraging people to leave their computers unlocked i…

I can see you don't, which is why I'm trying to pose it variously.

It's a simple one: why make it easier for a user to be compromised than is necessary? Why is it such a problem to ask the user to enter their account password before viewing this prefpane? You've not provided a valid argument against this.

As to lulling users - they already are. All of your marketing screams about how secure chrome is, how you don't need to worry about security, and all the rest, so showing their plaintext passwords just seems... silly.

Re: Chrome's insane password security strategy

#96

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

That fact that you tell him he is wrong and never really explain the "why" makes me not believe you. What little explanation you do give is the abstinence argument. It sounds great but it is not what people are doing.

Also, I think someone like a thief, jealous spouse, unscrupulous roommate or coworker or the like is much more likely to try and get someone's password to do evil with. The way Chrome is now, all a person needs is 4 or 5 minutes alone with the computer to get the user's passwords.

Re: Chrome's insane password security strategy

#97

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

[deleted]

Re: Chrome's insane password security strategy

#98

I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…

Nobody doubts that adding a master password will stop nobody who knows what they are doing. If someone has access to your computer and wants to do damage, they have full access to do it.

However, keep in mind 'open door' syndrome. A crime of opportunity is very different than one of bad intentions. Leave a car unlocked with a $20 bill on the seat and you might find that $20 gone when you return. Now, if you lock the doors the odds are it will still be there when you return. The fact is that when you increase the barrier to doing evil, many give it up. A potentially honest person might open a door and take something but if they must now break a window to accomplish the same task many will not pursue it.

Having to potentially download a third party program to decrypt the password DB and/or run additional commands is very different that just navigating to the chrome settings page. Its almost akin to why so many coworkers always jacked each others wallpaper when they forgot to lock their computer. They could have still done it even though the computer was locked, but they did not because it was too much work.

Also, going off what you have said, the "locking" process in windows is pointless since it offers a false sense of security. It can be broken just by rebooting the computer with a boot disk, right? So why include it? Because its useful.

Re: Chrome's insane password security strategy

#99

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

Elliot's right: Chrome's way of storing and presenting passwords is unacceptable and less than fully sane.

Re: Chrome's insane password security strategy

#100

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

justin: other applications offer an added layer of security through a master password, which chrome does not, are you saying that this has 0 affect of the level of security surrounding the stored passwords? Or are you saying chrome(ium?) uses the same technique but hidden to the user?

Not just other applications - MacOS's own Keychain application requires the user to re-enter their login password in order to see passwords that were saved in their user keychain. This is to ensure that while you might be able to make use of those passwords if you have physical access, you won't be able to easily copy them off somewhere else.

Please Justin, explain the real reason that Chrome does this, or admit that it's a bug and get it fixed. The reasons you mention are just stupid.

Post reply on HN