Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

131–140 of 315 posts

Re: Chrome's insane password security strategy

#131

Earlier quoted context omitted.

Elliottkmember is right here. Chrome's approach to this is absurd. What if you simply don't want friends, coworkers, significant others browsing your passwords? At least tell users that if they choose to save passwords in Chrome, that everyone who uses their computer, even pretty non-technical people, will be able to access those passwords. Tell them that storing their passwords in Chrome is unsafe. Justin, can you t…

Please don't invent motivations for the statements people make when you don't like what they've stated so far. If you don't want people browsing your passwords, you can't ever give them access to your user account or your unlocked desktop. That's it, that is the entire solution. Any other method of protecting the passwords is vulnerable as long as the potential attacker has physical access to the unlocked desktop. No…

>If you don't want people browsing your passwords, you can't ever give them access to your user account or your unlocked desktop. That's it, that is the entire solution.

Nope.

Just don't use Chrome. That's an even better solution.

Re: Chrome's insane password security strategy

#132

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

fwiw Pidgin takes this same approach for the same reasons. https://developer.pidgin.im/wiki/PlainTextPasswords "locking" the passwords would require intermittent master-pass entry like `sudo`, this would come off as an inconvenience to many users. I think people here miss the fact that many users, even if they say they want more security, are unwilling to give up convenience and will switch platforms (i.e. browsers)…

However, Pidgin “would encourage integration with keyrings” [0]. At least on OS X Chrome uses the integrated keychain and as Elusive mentioned [1] it apparently does encrypt passwords on Windows too.

So, I think Pidgin’s situation is a bit different and if they would have keychain integration they may solve this differently than Chrome does right now.

[0]: https://developer.pidgin.im/wiki/PlainTextPasswords#Isthatth... [1]: https://news.ycombinator.com/item?id=6168039

Re: Chrome's insane password security strategy

#133

Earlier quoted context omitted.

justin: other applications offer an added layer of security through a master password, which chrome does not, are you saying that this has 0 affect of the level of security surrounding the stored passwords? Or are you saying chrome(ium?) uses the same technique but hidden to the user?

Not just other applications - MacOS's own Keychain application requires the user to re-enter their login password in order to see passwords that were saved in their user keychain. This is to ensure that while you might be able to make use of those passwords if you have physical access, you won't be able to easily copy them off somewhere else. Please Justin, explain the real reason that Chrome does this, or admit that…

[deleted]

Re: Chrome's insane password security strategy

#134

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

There is a simple fix for this and FireFox uses it. Simply, allow users to create a master password to view stored passwords. They don't need to be asked to enter it every time they log into sites so the ease of use remains. But, if a stranger gets a hold of their machine, they will be one giant step farther from retrieving their passcodes. PS. This was always an issue with Chrome, and it is why I don't use Chrome on…

May I ask what similar problem Safari has?

As far as I know, Safari uses OS X’s keychain which means you practically have a master password (very likely your user account password, although you could use a different keychain). If I try to retrieve a password (either through Keychain Access or Safari’s Preferences) I get asked for my “master password”.

Re: Chrome's insane password security strategy

#135

Earlier quoted context omitted.

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I think Justin's arguments are fair.

The reality is that you're using the browser under a certain user profile. If you want to really separate your data from other users using your computer i would suggest icognito sessions or creating different user profiles. If you share your user profile (active user) you expose all this data (bookmarks, extensions, passwords).

Seems logical to me

https://www.dropbox.com/s/kgrrtil2s7hi43j/Screenshot%202013-...

Re: Chrome's insane password security strategy

#136

Earlier quoted context omitted.

Completely agree here. This isn't about providing a sense of security as much as making it more difficult for co-workers or even friends to steal each other's passwords. Just because I forgot to lock the door of my house, doesn't mean I shouldn't be allowed to hide and secure some valuables I don't want stolen that easily.

If chrome ever removes that setting, I will make chromereveal.com with one-click idiot-proof password dumping tool, and step-by step instructions. So hiding that button will not make it harder for your friends. Just logout and give them guest access...geez.

that does make it psychologically harder - I have to go to a site with clear malicious intention, rather than pay a visit to a setting which the browser itself provides.

Re: Chrome's insane password security strategy

#137

Earlier quoted context omitted.

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

Justin is right. This is why the browser I'm working on flashes your passwords in plaintext ever few seconds. Let's not pretend an attacker couldn't look over your shoulder anyhow.

Re: Chrome's insane password security strategy

#138
post #2

I just did a little digging just by visiting some sites I've saved passwords for (in Safari) using Chrome. Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy. When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting…

Er, are you sure? I just tried this with Facebook and what you describe did not happen.

The access control tab in the keychain entry had Safari as the only listed application. When I then visited the site in Chrome, it asked for permission to access the keychain. When I clicked "Allow" it worked, but Chrome was not added to the "Always allow access by these applications" list and re-prompted when I refreshed the page. When I then clicked on "Always Allow", it added Chrome to the application access list, and I'm no longer prompted for access to the keychain.

At no point was an additional entry added to the keychain.

I did notice that when Safari offered to remember the password, with an additional option to make it so that only Safari could access that password. Is it possible that you clicked on that and Chrome had to create a new entry?

Edit: I tried getting that option again to test setting it, deleting the facebook entry in the keychain and then logging in again in Safari. It no longer asks me if I want only Safari to have access to that...not sure why it won't.

Re: Chrome's insane password security strategy

#139

Earlier quoted context omitted.

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

Agreed. Normal non-technical people let friends have a look at their computer, and it is often a surprise for both that passwords can so easily be seen. Theory is one thing, but there is IMHO also a practical "don't make it too easy" factor that should be considered. As the saying goes, sometimes "opportunity makes a thief".

Re: Chrome's insane password security strategy

#140

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

Before I start my reponse proper, I should point out that I know most other browsers, and most add-ons for them that perform the task of storing credentials, do much the same thing and are therefor no less insecure. This is why I recommend everyone avoid most credential storing products and turn off their browser's built-in facility (whichever browser they use).

> I appreciate how this appears to a novice

As you are in the process of defending storing passwords in plain form (or at least in a manner that allows them to be accessed in plain form so easily), without any warning that this is happening, I am of the opinion that you have no right to be so condescending as to publicly call someone else a novice.

> but we've literally spent years evaluating it

Some creationists have spent decades evaluating their position too. That does not make my any more inclined to agree with their assessment of the way the universe works, nor does it make me feel inclined to recommend that position to others.

> and have quite a bit of data to inform our position.

Please provide said data so that we can evaluate it, otherwise what you are saying here is simply "I'm right because I know that I'm right".

> what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

That is EXACTLY how you are approaching security in Chrome it would seem.

If the criticism of the way Chrome currently does these things is wrong for this reason then Chrome's behaviour is wrong for the same reason. Users will assume that the passwords are stored securely, or will be blissfully unaware that they even need to be, and will think they are safe when they are not. This argument may not make the alternate suggestion being made correct, you certainly believe that it is not, but your argument doesn't make Chrome's current position any less incorrect either.

While here we all know that locking out workstations provides much better security (as mentioned in your earlier post) than a master password on the browser's credentials store would, the general public do not tend to have much concept of that in my experience (while it very much should be, it is not something most people give any thought to unless explicitly prompted). Letting them take their ignorance of the matter one step further is lulling them further into a false sense of security.

You are not wrong in stating that users should lock their workstations when leaving them, and should have them set to auto-lock after a time in case they forget. Likewise we are not wrong in stating that any key store should be locked after use, and automatically locked after a period of inactivity (requireing the master password to be requested again).

Essentially you are silently opting in (on the user's behalf) to exchanging security for convenience. This brings us full circle, back to the word "novice".

With regard to my earlier acknowledgement that other vendors do the same thing, while I'm taking cheap shots like the "novice" thing above: "other people are doing it" is no more a valid excuse for irresponsable behaviour here than it was in the school playgound when we were five.

We (by "we" I'm including developers, DBAs, technical managers, security experts, and other members of the technical "community") should be trying to teach users to take better care of their credentials and their information security more generally, making it inconvenient for them not to if neccessary rather than making it easy for them to continue to be blissfully ignorant of the situation.

Post reply on HN