Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

121–130 of 315 posts

Re: Chrome's insane password security strategy

#121

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

You're right, locking the operating system will secure it. But people aren't doing that. And people lend their computers to friends sometimes. It happens. I think the actual situation is that you don't understand how people are using computers, and how people expect them to behave - which is very important. Your software allows me to open up one application and see all passwords. It's likely the single most-used appl…

1) Chrome doesn't show "all passwords". It only shows passwords that Chrome knows about. The two categories might overlap, but they're not actually the same.

2) Either the browser demands an unlock password every single time it queries the password store--which is probably not an acceptable experience for most users--or the browser can arbitrarily read the password store when left unattended. There's no meaningful middle ground here. An option to demand a credential before unlocking the store might be nice for nerds, but nerds don't need it anyway, because they can use 1Password (or similar) to do this for them. It's simply not tenable for normals. Good grief, just look at the wailing and moaning that the UAC prompts in Windows Vista generated. Those prompts by default didn't even demand credentials, just a click through.

Re: Chrome's insane password security strategy

#122

Earlier quoted context omitted.

Elliottkmember is right here. Chrome's approach to this is absurd. What if you simply don't want friends, coworkers, significant others browsing your passwords? At least tell users that if they choose to save passwords in Chrome, that everyone who uses their computer, even pretty non-technical people, will be able to access those passwords. Tell them that storing their passwords in Chrome is unsafe. Justin, can you t…

Please don't invent motivations for the statements people make when you don't like what they've stated so far. If you don't want people browsing your passwords, you can't ever give them access to your user account or your unlocked desktop. That's it, that is the entire solution. Any other method of protecting the passwords is vulnerable as long as the potential attacker has physical access to the unlocked desktop. No…

Right, I'm not arguing against any of that. The point is if it's going to be that insecure, Chrome should make more of an effort to make it clear. They could do this by displaying a warning alongside the prompt to save a password.

Also, just because some people will be able to access the passwords with physical access doesn't mean it's not worth doing basic/unsecure locking. I'd rather use a system where people need to have the know how to use keyloggers in order to break, over one where Joe Schmoe can walk in and take everything.

In the end I have always known the security issues with saving passwords so I don't save any banking passwords or email account passwords in any browser.

Re: Chrome's insane password security strategy

#123
post #98

I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…

Nobody doubts that adding a master password will stop nobody who knows what they are doing. If someone has access to your computer and wants to do damage, they have full access to do it. However, keep in mind 'open door' syndrome. A crime of opportunity is very different than one of bad intentions. Leave a car unlocked with a $20 bill on the seat and you might find that $20 gone when you return. Now, if you lock the…

Completely agree here. This isn't about providing a sense of security as much as making it more difficult for co-workers or even friends to steal each other's passwords.

Just because I forgot to lock the door of my house, doesn't mean I shouldn't be allowed to hide and secure some valuables I don't want stolen that easily.

Re: Chrome's insane password security strategy

#124

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

You're assuming your users will go to that place, see their passwords are showing and say to themselves, 'ok, this stuff isn't secure, I better be careful'. But that doesn't happen. People don't generally go there. They don't know about it. But someone else, using their computer, might know about it, or might stumble upon it. If you stop this happening, people aren't going to be lulled into a false sense of security, as you suggest. They aren't even going to know it happened. But their passwords will be more secure against casual discovery.

Re: Chrome's insane password security strategy

#125
post #85

Earlier quoted context omitted.

You're still missing the point, and you're scarily out of touch. A novice (I use my mother as my reference novice) has NO IDEA how to go about changing a form field type, but does know how to drill into preferences and look at passwords-on-a-silver-platter. If you honestly think that the average user knows how to crack, hack and phreak, you're on another planet. I cannot comprehend what useful purpose showing the pas…

I'm sorry, but I really do understand your argument. You're claiming that the same novice who can't install a simple application or or follow three steps to reveal a password on the page will be capable of drilling down through the Chrome settings menus and displaying passwords. The corollary to your claim is that the threat of this novice outweighs the damage of encouraging people to leave their computers unlocked i…

Man, you are insane.

Re: Chrome's insane password security strategy

#126

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

If you don't want to lull your users into a false sense of security, then why doesn't the "save password?" dialog have a disclaimer reading, "All saved passwords can be viewed at chrome://settings/passwords". This simple notification would go a long way towards raising the level of awareness you seem to assume the average person already has.

Re: Chrome's insane password security strategy

#127

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I won't be using Chrome again until this behavior can be turned off.

You can just uncheck the 'offer to save passwords ...' mark within the settings of Chrome.

I've removed all stored passwords and stick closely to 1Password now.

Re: Chrome's insane password security strategy

#128
post #78

Earlier quoted context omitted.

But it is a false sense of security. Joe User doesn't know a thing about how this magical box of tricks called a computer works. He just assumes that his data is safe on it, and won't get into the wrong hands, and that his passwords will always be protected by asterisks or what-not. Sure, you may encrypt them using keychain, which is good, and yes, if someone has physical access to their machine and user account then…

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

There is a serious problem with your logic here. The only way to protect you OS user account is by encrypting it. I would bet a LOT of money that the majority of Chrome users have never even heard of encryption let alone implemented it. To even have Chrome remember passwords when it runs on systems that doesn't require a user to configure a password is a mess. There should at least be a warning to users that if they choose to have Chrome remember a password there is a very high risk of that password being compromised.

Re: Chrome's insane password security strategy

#129
post #98

Earlier quoted context omitted.

Nobody doubts that adding a master password will stop nobody who knows what they are doing. If someone has access to your computer and wants to do damage, they have full access to do it. However, keep in mind 'open door' syndrome. A crime of opportunity is very different than one of bad intentions. Leave a car unlocked with a $20 bill on the seat and you might find that $20 gone when you return. Now, if you lock the…

Completely agree here. This isn't about providing a sense of security as much as making it more difficult for co-workers or even friends to steal each other's passwords. Just because I forgot to lock the door of my house, doesn't mean I shouldn't be allowed to hide and secure some valuables I don't want stolen that easily.

If chrome ever removes that setting, I will make chromereveal.com with one-click idiot-proof password dumping tool, and step-by step instructions. So hiding that button will not make it harder for your friends.

Just logout and give them guest access...geez.

Re: Chrome's insane password security strategy

#130
post #78

Earlier quoted context omitted.

But it is a false sense of security. Joe User doesn't know a thing about how this magical box of tricks called a computer works. He just assumes that his data is safe on it, and won't get into the wrong hands, and that his passwords will always be protected by asterisks or what-not. Sure, you may encrypt them using keychain, which is good, and yes, if someone has physical access to their machine and user account then…

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

"For every complex problem there is an answer that is clear, simple, and wrong." Congrats on finding it!
Post reply on HN