Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

151–160 of 315 posts

Re: Chrome's insane password security strategy

#151
post #10

To those saying this isn't insane... you are wrong. I can open anyone's chrome browser and access their passwords without a master password? That's plain fucked up. (I realise I could visit sites and use password reset, but this is so frictionless as to be insane)

You can't open my chrome browser without unlocking my machine. You can't unlock my machine without 2fa. I don't walk away from my machine without locking it. So, technically, there is a master password if you lock your machine. Nb:not saying it is cool to be doing what they're doing.

The data on your disk isn't encrypted with two factor authentication though. If someone were to remove your disk drive and crack your password, that second factor doesn't really slow them down.

Re: Chrome's insane password security strategy

#152

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

Sometimes you get glimpses into the inner sanctums of Google that make it seem like it's a culture of robots. Their first responses to outrage over the Google Maps cars they'd sent out to hoover people's wi-fi information were similarly obtuse about the mysterious ways of the non-machines: It's all information that was freely available to anyone who happened to have a fleet of packet-sniffing vehicles anyway, so what…

You're reading way too much into this. But I kinda like it, so proceed.

Re: Chrome's insane password security strategy

#153
post #78

Earlier quoted context omitted.

But it is a false sense of security. Joe User doesn't know a thing about how this magical box of tricks called a computer works. He just assumes that his data is safe on it, and won't get into the wrong hands, and that his passwords will always be protected by asterisks or what-not. Sure, you may encrypt them using keychain, which is good, and yes, if someone has physical access to their machine and user account then…

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

[deleted]

Re: Chrome's insane password security strategy

#154
post #109

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

If I have access to your browser, I can get your credentials for Amazon by just going to Amazon.com . Either you already have a session open, and then I can do what I want (including changing your password), or the browser (or your password manager) is going to fill in the password automatically, and with a trivial knowledge of how the browser works I can copy the password. I use LastPass, and it is possible to set i…

Did you test your assertion?

Go to amazon right now and try to change your password without having to enter your password first.

Re: Chrome's insane password security strategy

#155

Earlier quoted context omitted.

You're right, locking the operating system will secure it. But people aren't doing that. And people lend their computers to friends sometimes. It happens. I think the actual situation is that you don't understand how people are using computers, and how people expect them to behave - which is very important. Your software allows me to open up one application and see all passwords. It's likely the single most-used appl…

1) Chrome doesn't show "all passwords". It only shows passwords that Chrome knows about. The two categories might overlap, but they're not actually the same. 2) Either the browser demands an unlock password every single time it queries the password store--which is probably not an acceptable experience for most users--or the browser can arbitrarily read the password store when left unattended. There's no meaningful mi…

Hm, I agree with the author of the article on this. I think, the default should be, that the user will be prompted to define a master password, which unlocks the password store. User might choose not wanting to set this password, but then he should be warned that all his stored passwords will be accessible by anyone using his computer with his credentials.

Re: Chrome's insane password security strategy

#156
post #109

Earlier quoted context omitted.

If I have access to your browser, I can get your credentials for Amazon by just going to Amazon.com . Either you already have a session open, and then I can do what I want (including changing your password), or the browser (or your password manager) is going to fill in the password automatically, and with a trivial knowledge of how the browser works I can copy the password. I use LastPass, and it is possible to set i…

Did you test your assertion? Go to amazon right now and try to change your password without having to enter your password first.

My browser fills in that password for me. My guess is that would be the same for most people.

Re: Chrome's insane password security strategy

#157

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

You're right, locking the operating system will secure it. But people aren't doing that. And people lend their computers to friends sometimes. It happens. I think the actual situation is that you don't understand how people are using computers, and how people expect them to behave - which is very important. Your software allows me to open up one application and see all passwords. It's likely the single most-used appl…

If you actually _want_ someone's password and you have access to their account, there are many things you can do, all equally easy.

The more interesting argument here is the "crime of convenience" - where someone didn't want the passwords, but just saw them laying around in plain sight. But that isn't actually the case in Chrome: it's like four clicks. You have to actually be trying to find them.

Re: Chrome's insane password security strategy

#158

Earlier quoted context omitted.

1) Chrome doesn't show "all passwords". It only shows passwords that Chrome knows about. The two categories might overlap, but they're not actually the same. 2) Either the browser demands an unlock password every single time it queries the password store--which is probably not an acceptable experience for most users--or the browser can arbitrarily read the password store when left unattended. There's no meaningful mi…

Hm, I agree with the author of the article on this. I think, the default should be, that the user will be prompted to define a master password, which unlocks the password store. User might choose not wanting to set this password, but then he should be warned that all his stored passwords will be accessible by anyone using his computer with his credentials.

"his stored passwords will be accessible by anyone using his computer with his credentials."

But this is EXACTLY Justin's point: EVEN with a master password, they'd be accessible in other ways by anyone using his computer, because it's just stored in the keychain - and if they add a master password, people will think that makes it more secure.

The solution here is to remove the show button - don't add any kind of master password - because that's just snake oil.

Re: Chrome's insane password security strategy

#159

Earlier quoted context omitted.

Er, are you sure? I just tried this with Facebook and what you describe did not happen. The access control tab in the keychain entry had Safari as the only listed application. When I then visited the site in Chrome, it asked for permission to access the keychain. When I clicked "Allow" it worked, but Chrome was not added to the "Always allow access by these applications" list and re-prompted when I refreshed the page…

Am I sure? Well I was tripping balls on acid at the time so no /sarcasm

Let me rephrase: on a default, clean Chrome install on 10.8.4, you are wrong. If you can't find some exculpatory evidence, I'm going to assume user error, perhaps in how you have your keychain set up.

Meanwhile I see no bug on https://code.google.com/p/chromium/issues/list filed today on the topic, and you obviously don't use Chrome as your primary browser, so I'm not going to worry about you. Cheers.

Re: Chrome's insane password security strategy

#160

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

I take it that you are unaware of the concept of defense in-depth, because your argument is essentially: well if they can come in the front door, then they can open the garage & steal my car too easy, so putting lock on the doors would make people think their car was secure. To enable a person to lock the car door would be silly because once a person has access to your house, they own everything in it. While no security measure is perfect, and with enough motivation & resources anything can be cracked, making things a bit more difficult with master password locking, etc. will stop casual security breaches: I.e. a boyfriend/girlfriend finds out their SO uses Chrome, so he/she steals their SO’s passwords from Chrome in seconds to later use against them after a break up, or to monitor them, etc. This happened (to a friend of mine BTW) and had Chrome had a master password, the SO would never have been able to do it because most people do not have the resources available to do it, an those people are the most irresponsible with having access. This thought that by making something less secure, you are in fact helping the user from having a false belief—that they are secure—is an ignorant decision at best because nothing is secure, but things can be more secure. & from I have learned balancing convenience & security usually falls somewhere between. a 5 second to breach to breach security policy (Chrome) is no where near (the standard) 5 seconds to unlock by typing in a master pass with a default 10 minute idle lock.

Basically, you are fighting ignorance with even greater ignorant decisions.

Post reply on HN