Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

211–220 of 315 posts

Re: Chrome's insane password security strategy

#211
post #207

Earlier quoted context omitted.

You say you do not wish to lull users into a false sense of security. So why not clearly tell people each time Chrome saves a password that the saved password will be visible in plaintext by visiting chrome://settings/passwords ? Otherwise you are lulling people into a false sense of security. E.g., to view passwords in my coworker's Keychain, I have to at least enter their account password to show the plaintext. To…

So why not clearly tell people each time Chrome saves a password that the saved password will be visible in plaintext by visiting chrome://settings/passwords ? Because the vast majority of the population don't know what a browser is, let alone a URL. You (the developer) are providing the illusion of consent. The person don't know what just happened, but you're inferring that they have consented to what it showing up…

So Chrome should not allow passwords to be read without the system Keychain password.

There is no technical reason it can't do this. Safari does this if you want to view passwords.

Chrome makes passwords casually available, this is unlike Safari and unlike the Keychain. So either Chrome informs the user of that behaviour or it stops doing it.

What it is doing now is very poorly designed behaviour. I am surprised that you are arguing for Chrome's current implementation.

I fail to see how it is beneficial to the user. As you say, most non-technical users don't know about chrome://settings/passwords, these are also the group of users who most likely need to be reminded of their passwords. So what Chrome is doing is essentially allowing slightly technically competent users to easily peek at the passwords of the "vast majority of the population." Bad design that is easily fixed.

Re: Chrome's insane password security strategy

#212

Earlier quoted context omitted.

On OS X Chrome pulls the passwords out of the keychain and then makes them completely accessibly in plaintext through the settings/passwords page. I have no idea why it does this.

How open of a platform is that keychain, and can Apple reserve the right to lock any aplication out?

Keychain is accessible through standard system API calls.

Apple does not require any sort of approval or valid developer certificate to use the Keychain. Any app that attempts to access the Keychain will trigger a system-level notification to the user informing them of what the app wants to access, and allowing the user to "Allow", "Deny" or "Always Allow" the request.

Re: Chrome's insane password security strategy

#213

Earlier quoted context omitted.

I don't know what you're thinking. Storing multiple encrypted passwords behind a single "master" password (in the case of Windows and OSX its usually the OS level User password) is a common way to provide convenience and security for users.

Well, that's what a login password and a lockscreen are for. I mean, these things are secure and well-tested - I'm not sure why people aren't using them? Do you somehow think that your OS is more insecure? I don't think you've exactly explained what exactly you're trying to protect against. Is it casual attacker who happen to chance upon an unattended computer? Well, in that case, either your computer is locked, or i…

My issue is that chrome blatantly ignores the user's decision about when it can access a stored password, and creates its own copy, giving itself arbitrary access to said item.

This doesn't affect me personally in the slightest, I don't use Chrome for anything but debugging, but claiming this is anything other than Google doing what Google does best (fucking the user) is short sighted.

Re: Chrome's insane password security strategy

#214

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

The threat model hiding the passwords wants to address is not about thieves, criminals, 'bad guys' etc.. Instead it's about protecting your password from jealous boy/girlfriends, friends who want to prank you, curious kids, etc., while you leave the room for a couple of minutes.

In many situations its cumbersome or not socially acceptable to log out if someone just wants to use your browser for a second, because that implies you mistrust the other person. On the other hand, you wouldn't necessarily give the other person your passwords, of course.

I guess what many people expect is that passwords you save in the browser should be really hard to get out. There should be a function to recover them, because it can really be a life saver, and because it would give a false sense of security otherwise. But this function should be in a separate tool, and it could be really cumbersome to use (only runs in safe mode, is a command line tool, displays a full screen warning in red on black, plays a loud fanfare :-), etc.). It should be the equivalent of taking a bolt cutter to your bicycle lock, when you lost the key.

What people want here is not more security in a strict technical sense. Most people understand that you should log out, and if necessary enable disc encryption and/or physically secure your computer, to be safe against "bad guys". What people want in addition to this is a layer of obscurity, a social speed bump. Something that makes it inconvenient for nosey people to see your passwords, that adds friction and shows them they are doing something wrong.

(Oh, and having a master password (that is forgotten after a few minutes) does offer perfect protection against anybody who doesn't know how to install a keylogger etc.. I guess I and many other people are mainly worried about "foes" that are not so technically adept.)

Re: Chrome's insane password security strategy

#215

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I can do this in firefox too... Tools...options...saved passwords....show passwords... So I'm missing the point why it makes Chrome so bad?

before the "show passwords" button, there is a "use a master password" option that is unticked by default.

Generaly tho, i don't have any passwords there (all of them are in lastpass), except a few email account ones. Why do i have ANY passwords there? Well, they are being used by an extension that sort of needs them to push notifications about emails. I do have them protected by a master password, but the extension can still acess them. However, the extension has an option to ask for the password if i click one of the mailboxes in its menu. But then again i can still bypass that if i type the adress of one webmail provider, because i will get credentials for it. A good way around it would be if that extension developer would integrate with lastpass somehow, but does lastpass allow that? Now or in the future forevermore?

Re: Chrome's insane password security strategy

#216

Earlier quoted context omitted.

Hm, I agree with the author of the article on this. I think, the default should be, that the user will be prompted to define a master password, which unlocks the password store. User might choose not wanting to set this password, but then he should be warned that all his stored passwords will be accessible by anyone using his computer with his credentials.

"his stored passwords will be accessible by anyone using his computer with his credentials." But this is EXACTLY Justin's point: EVEN with a master password, they'd be accessible in other ways by anyone using his computer, because it's just stored in the keychain - and if they add a master password, people will think that makes it more secure. The solution here is to remove the show button - don't add any kind of mas…

>EVEN with a master password, they'd be accessible in other ways by anyone using his computer

Maybe (there are simple but very effective prevention methods against keyloggers etc.), but the main point is: it's not all black and white. There are varying levels of security (and varying levels of "hacker skills"). Passwords encrypted with a master password are at least a couple of levels safer than those displayed in plain text.

Re: Chrome's insane password security strategy

#217
post #199

Earlier quoted context omitted.

Someone who can access your computer, unlocked, can login to your Facebook account (the password is saved), change the password, verify the email, re-save the new password, and it's just as easily "game over". You would never know what happened. Justin is absolutely right. His group is doing users a service by making these things more transparent. Folks who make exceptions based on this "security through obscurity" m…

Changing the password is a fair point that I hadn't considered

I think that most people on here haven't considered this. In fact, I arrived at your comment by searching the page for "reset". The majority of folks seem too focused on trying to outclass Justin and/or getting in the last word. They're not thinking. Just for fun, I went to see how many licks it actually does take to get to the center of a tootsie roll pop i.e., clicks to reveal a password using the passwords dialog box in Chrome? There are about 27 keyboard button presses for the URL, then a mouse click for the Show button. Fair enough. Too bad I can get to the password reset field in Facebook in 3 mouse clicks, using my bookmarks bar. I'm pretty sure that I won't need 25 more clicks for the verification email. So if we're all just gauging security by how difficult you can make getting at a password, then I beat Justin. And my "exploit" is platform independent.

Re: Chrome's insane password security strategy

#218
post #95

Earlier quoted context omitted.

I'm sorry, but I really do understand your argument. You're claiming that the same novice who can't install a simple application or or follow three steps to reveal a password on the page will be capable of drilling down through the Chrome settings menus and displaying passwords. The corollary to your claim is that the threat of this novice outweighs the damage of encouraging people to leave their computers unlocked i…

I can see you don't, which is why I'm trying to pose it variously. It's a simple one: why make it easier for a user to be compromised than is necessary? Why is it such a problem to ask the user to enter their account password before viewing this prefpane? You've not provided a valid argument against this. As to lulling users - they already are. All of your marketing screams about how secure chrome is, how you don't n…

> Why is it such a problem to ask the user to enter their account password before viewing this prefpane?

You're trying to prevent my friends from fetching my email password to look secretly at my self-nude pictures.

Justin is trying to prevent my enemies from fetching my email password to gain access to my bank account and rob me of all my money.

His point is Chrome preventing the former threat, while useful by itself, can lead me to believe that I'm also protected against enemies with physical access. This belief, as we know, makes preventing the latter threat impossible. As he cares way more about the latter threat, he thinks it's counterproductive to defend against the former.

> All of your marketing screams about how secure chrome is

To be fair, that refers to being secure against remote attackers, which is the primary concern of a browser since there's not much the user can do about it by himself.

Re: Chrome's insane password security strategy

#219

Earlier quoted context omitted.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

Your logic doesn't follow. According to your rules we shouldn't have doors on houses as all they do is provide a false sense of security.

Don't forget, all security, regardless of how good it is, is just a delay mechanism. It's perfectly valid to delay the easy attacks as well as the hard ones.

Re: Chrome's insane password security strategy

#220

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

Let us use Google's web approach to various services to better explain this. When I login to my gmail, and open up google docs, or youtube on a different tab, I am logged in by default. However, when I go to edit my Google Account Settings, I am again prompted for a password, right?

If what you said about studying threat models and securing your computers and users accounts before handing over the system to friends or family is true and valid, why am I being asked a password to edit my Google Account settings. By extension of your claim, I should never have been handing over my system with a logged in user to anybody else. And definitely, the other claim that providing an extra layer of security is a false pretense must be valid in that Google is just providing us a false pretense of security when we want to edit our Google Account Settings which it does not require when we try to edit settings of the individual services?

Why is this distinction between Google's web services and your browser security?

Post reply on HN