Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

221–230 of 315 posts

Re: Chrome's insane password security strategy

#221

I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…

Please tell me why everything needs to be taken so seriously. You wrote: "...bad guy can dump all your session cookies, grab your history, install malicious extension to intercept all your browsing activity, or install OS user account level monitoring software..." It sounds like that computer owns nuclear bomb instructions. Take a breath and one step back: How about if the kids likes to play with their friend and lik…

> It sounds like that computer owns nuclear bomb instructions.

That computer, for many people, owns ways to access their online bank account. That's why Justin et al. need to take it so seriously.

Re: Chrome's insane password security strategy

#222
post #148

I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…

That's fair enough but then why put in a giant 'SHOW PASSWORD' button. Why not just remove that button. I expect a hacker using my computer with admin rights to get everything. I don't expect my GF to get my passwords simply by pressing the 'show passwords' button. And it's not very realistic for me to tell my GF she can't use my computer or to log out every time I give it to her. She's going to be kind of insulted i…

> I expect a hacker using my computer with admin rights to get everything.

Problem is a certain amount of people don't expect that, and it's important that this group doesn't grow.

Re: Chrome's insane password security strategy

#223
post #207

Earlier quoted context omitted.

So why not clearly tell people each time Chrome saves a password that the saved password will be visible in plaintext by visiting chrome://settings/passwords ? Because the vast majority of the population don't know what a browser is, let alone a URL. You (the developer) are providing the illusion of consent. The person don't know what just happened, but you're inferring that they have consented to what it showing up…

So Chrome should not allow passwords to be read without the system Keychain password. There is no technical reason it can't do this. Safari does this if you want to view passwords. Chrome makes passwords casually available, this is unlike Safari and unlike the Keychain. So either Chrome informs the user of that behaviour or it stops doing it. What it is doing now is very poorly designed behaviour. I am surprised that…

There is no technical reason it can't do this.

Not all OSes have a "Keychain".

Re: Chrome's insane password security strategy

#224

Earlier quoted context omitted.

I appreciate how this appears to a novice, but we've literally spent years evaluating it and have quite a bit of data to inform our position. And while you're certainly well intentioned, what you're proposing is that that we make users less safe than they are today by providing them a false sense of security and encouraging dangerous behavior. That's just not how we approach security on Chrome.

If you don't want to lull your users into a false sense of security, then why doesn't the "save password?" dialog have a disclaimer reading, "All saved passwords can be viewed at chrome://settings/passwords". This simple notification would go a long way towards raising the level of awareness you seem to assume the average person already has.

Then they might chose to use IE instead, which doesn't show that disclaimer yet is no different. The teaching that needs to be done is that letting a bad guy access your computer unlocked is game over.

Re: Chrome's insane password security strategy

#225

I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…

Consider a case of some average user(who doesn't have the skills of your said bad guy) got on your computer while you are away, he can easily view your password to all your online account that's accessed on your browser.

Re: Chrome's insane password security strategy

#226
post #216

Earlier quoted context omitted.

"his stored passwords will be accessible by anyone using his computer with his credentials." But this is EXACTLY Justin's point: EVEN with a master password, they'd be accessible in other ways by anyone using his computer, because it's just stored in the keychain - and if they add a master password, people will think that makes it more secure. The solution here is to remove the show button - don't add any kind of mas…

>EVEN with a master password, they'd be accessible in other ways by anyone using his computer Maybe (there are simple but very effective prevention methods against keyloggers etc.), but the main point is: it's not all black and white. There are varying levels of security (and varying levels of "hacker skills"). Passwords encrypted with a master password are at least a couple of levels safer than those displayed in pl…

If they're autofilled, which is the very reason to store them, then it doesn't matter how deep you store them. The browser will dig it for you automatically.

Re: Chrome's insane password security strategy

#227

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

>> it's all just theater and won't actually stop anyone willing to invest minimal effort. So are all the policies and procedures of the TSA, if not the entire agency itself, but nobody is suggesting that making it a tiny bit harder to get weapons onto planes isn't a worthwhile goal. We argue over implementation details.

I read in a Tom Peters book years ago that if a flyer sees a coffee-stained tray table, they assume the airline doesn't maintain its aircraft. That's an utterly irrational conclusion -- and a typically human one. The solution is trivial: clean the tray tables! SO back to software.

Make it a tiny bit harder for ANY user to view the plain-text versions of the passwords stored in a web browser.

Re: Chrome's insane password security strategy

#228
post #199

Earlier quoted context omitted.

Someone who can access your computer, unlocked, can login to your Facebook account (the password is saved), change the password, verify the email, re-save the new password, and it's just as easily "game over". You would never know what happened. Justin is absolutely right. His group is doing users a service by making these things more transparent. Folks who make exceptions based on this "security through obscurity" m…

Changing the password is a fair point that I hadn't considered

Don't most sites require that you enter your old password before you can change it?

Re: Chrome's insane password security strategy

#229
post #228
post #199

Earlier quoted context omitted.

Changing the password is a fair point that I hadn't considered

Don't most sites require that you enter your old password before you can change it?

Indeed, I guess this is a +1 against storing passwords plaintext (well, obtainable in any case) - as a person could change your password and take over the account completely

Re: Chrome's insane password security strategy

#230
post #85

Earlier quoted context omitted.

You're still missing the point, and you're scarily out of touch. A novice (I use my mother as my reference novice) has NO IDEA how to go about changing a form field type, but does know how to drill into preferences and look at passwords-on-a-silver-platter. If you honestly think that the average user knows how to crack, hack and phreak, you're on another planet. I cannot comprehend what useful purpose showing the pas…

I'm sorry, but I really do understand your argument. You're claiming that the same novice who can't install a simple application or or follow three steps to reveal a password on the page will be capable of drilling down through the Chrome settings menus and displaying passwords. The corollary to your claim is that the threat of this novice outweighs the damage of encouraging people to leave their computers unlocked i…

The value, I think, is in challenging your own beliefs.

To be honest this reminds me a lot of how Microsoft used to treat issues in their code/software 'Oh, that's a user error. That's not a bug, that's a feature!'. And then when you get pushback you go 'I've discussed this enough, no more talking with the plebes'.

Your axiom seems to be that anyone with access to your computer should be 'trusted'.

In other words, if I hand my laptop to my spouse I am essentially granting her root privileges.

A lot of us are making the point that this isn't true. I may have a wife, children or a roommate who I trust to use my laptop but don't want to make my passwords easily visible.

When I hand my laptop to my wife I have an expectation that without resorting to some special tools she should not be able to find out what my Amazon password is or what my hotmail password is.

Your position seems to be that by making these passwords visible you are encouraging more secure behavior - ie. I will now log my computer into a 'guest' account every time I give it to my wife.

It just seems like you don't get how people ACTUALLY use your product. For many reasons I'm not going to lock my computer every time I give my laptop to my wife or a roommate. I have an expectation that there is SOME obscurity that protects my passwords even if it's just obscurity by not explicitly showing the password. You're not going to change my behavior and frankly most of us are pretty shocked that a) you are so resistant to challenging your own axioms b) you think this is somehow our fault for expecting Chrome to not have a giant 'show passwords' button.

You need to challenge your assumption that the 'attacker' is some malicious agent. Widen the scope to also include the suspicious spouse or the prankster roommate and you'll understand why we think this is a bigger deal than you seem to consider it. Even if it just presents a small barrier I think most of us feel that small 'annoyance' is enough to prevent pranks and snooping spouses.

Post reply on HN