Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

231–240 of 315 posts

Re: Chrome's insane password security strategy

#231

I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…

Door locks are the same thing. Crooks can just break a window. Who cares which is easier! Door locks provide a false sense of security.

For maximum effect, remove doorknobs to make sure people who can't even turn doorknobs can get in. Doorknobs provide a false sense of security.

Oh to hell with it. We can't have people lulled into a false sense of security, and educating customers is bad for biz. Doors themselves must go as well.

It's also key that we plant our feet on this issue regardless of what damn near every person on the planet would prefer: a deterrent against theft by someone unable or unwilling to break a window.

Re: Chrome's insane password security strategy

#232
post #227

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

>> it's all just theater and won't actually stop anyone willing to invest minimal effort. So are all the policies and procedures of the TSA, if not the entire agency itself, but nobody is suggesting that making it a tiny bit harder to get weapons onto planes isn't a worthwhile goal. We argue over implementation details. I read in a Tom Peters book years ago that if a flyer sees a coffee-stained tray table, they assum…

>> it's all just theater and won't actually stop anyone willing to invest minimal effort.

> So are all the policies and procedures of the TSA, if not the entire agency itself, but nobody is suggesting that making it a tiny bit harder to get weapons onto planes isn't a worthwhile goal.

Very large number of people have been, in fact, suggesting since day one of the TSA that the restrictions imposed on travel in the name of advancing security theater are not worth the costs that come with them, in some cases in some states (particularly Texas, but I think other states had started the process) going so far as moving to criminalize some of the TSA actions, until the TSA escalated by threatening to retaliate against Texas (who was the State where this had progressed farthest in the legislature) by shutting down all commercial air travel in/to/from the State if the bill was passed.

So, the basic premise of the analogy you are trying to use here is rather critically flawed.

Re: Chrome's insane password security strategy

#233

Earlier quoted context omitted.

You're right, locking the operating system will secure it. But people aren't doing that. And people lend their computers to friends sometimes. It happens. I think the actual situation is that you don't understand how people are using computers, and how people expect them to behave - which is very important. Your software allows me to open up one application and see all passwords. It's likely the single most-used appl…

If you actually _want_ someone's password and you have access to their account, there are many things you can do, all equally easy. The more interesting argument here is the "crime of convenience" - where someone didn't want the passwords, but just saw them laying around in plain sight. But that isn't actually the case in Chrome: it's like four clicks. You have to actually be trying to find them.

The point is that 4 clicks is a LOT more convenient than most people would expect.

Not to mention this doesn't seem to be an oversight by the Chrome team - it seems this is 'as designed'.

Re: Chrome's insane password security strategy

#234

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

Whoa, whoa, whoa. Let's all take a step back and try to see the forest for the trees. I read Mr. Kember's article (as well as numerous others linking to it around the web today) and what I read made me concerned enough to delete all of my passwords from Chrome until I understand a little more about the issue.

justinschuh seems to have a deep technical understanding of programming and program security so I will defer to his greater understanding and make sure that I secure access to my computer when I am not physically present.

With all of that, my concern is that justinschuh seems to believe that anyone who has physical access to my computer and wants to do something malicious will have a deep understanding of programming, and that is silly. What about my druggie cousin who comes to my birthday party. He has no programming skills, but if he knew one simple URL he now has passwords to my bank account, my Amazon account and a ton of other accounts that he can use to transfer money or otherwise feed his habit at my expense. Or how about my ex-wife who gains access to my laptop because my daughter needed it for a school project. Now my ex, who has zero programming knowledge, nor does she understand what "threat model" even means, has passwords to all of my accounts including Facebook and Twitter that she can use to seriously harm my social/professional life.

So, you see, I get that you understand the programmatic "threat model," my problem is that you seem to be too smart to see that not all threats come from tech savvy "hackers." Some threats just come from opportunistic malfeasors, and I don't need to add any new opportunities to the seemingly unending list of ways people can screw up my life.

Re: Chrome's insane password security strategy

#235

I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…

hmm.... i have a hard time agreeing with you justin. It's like saying once a thief is in your house, your game is lost anyways, so let's not put a lock on the door. You might be right on the point about the bad guy taking over the whole account and can do anything they want. But would it be a good thing for users if at least Chrome has strong password protection that makes the bad guy think twice about cracking them?

Re: Chrome's insane password security strategy

#236
post #149

Earlier quoted context omitted.

If chrome ever removes that setting, I will make chromereveal.com with one-click idiot-proof password dumping tool, and step-by step instructions. So hiding that button will not make it harder for your friends. Just logout and give them guest access...geez.

So you log out of your computer every time you give your computer to your wife?

Why do you assume that I have saved passwords (or anything else) on my computer to which my wife is not permitted access?

Re: Chrome's insane password security strategy

#237
post #218
post #95

Earlier quoted context omitted.

I can see you don't, which is why I'm trying to pose it variously. It's a simple one: why make it easier for a user to be compromised than is necessary? Why is it such a problem to ask the user to enter their account password before viewing this prefpane? You've not provided a valid argument against this. As to lulling users - they already are. All of your marketing screams about how secure chrome is, how you don't n…

> Why is it such a problem to ask the user to enter their account password before viewing this prefpane? You're trying to prevent my friends from fetching my email password to look secretly at my self-nude pictures. Justin is trying to prevent my enemies from fetching my email password to gain access to my bank account and rob me of all my money. His point is Chrome preventing the former threat, while useful by itsel…

Yeah but his point is really silly. He's trying to make the argument that by making it impossible to lock the car we won't leave valuables in it.

His argument is that since a person could just smash the windows and open the car that way there's no point in putting locks on the door.

It's just a very myopic and weirdly out of touch position. He seems to think that he's 'training' users to have more secure practices? This isn't the business world. You don't get to blame the user for not being security experts. He should be doing everything in his power to make it inconvenient and difficult to access a user's passwords.

Re: Chrome's insane password security strategy

#238
post #189

Earlier quoted context omitted.

"Inspect element" and then changing the "password" input type takes seconds/minutes.

Here are the issues with your method. - It's not as fast or inconspicuous as navigating to chrome://settings/passwords - It does not present all passwords in a single list with the ability to show the one I'm interested in - I would have to go to each site, allow Chrome to auto-fill, and then inspect the DOM and change the input type for each password I'm interested in. Far slower. - It feels far more malicious to do…

i'm surprised that you even answered him ...

Re: Chrome's insane password security strategy

#239

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

Whoa, whoa, whoa. Let's all take a step back and try to see the forest for the trees. I read Mr. Kember's article (as well as numerous others linking to it around the web today) and what I read made me concerned enough to delete all of my passwords from Chrome until I understand a little more about the issue. justinschuh seems to have a deep technical understanding of programming and program security so I will defer…

This is exactly my feeling too. Justin seems too smart by half.

His attitude is very much like an ivory tower academic who is befuddled that people don't follow best practices.

I also get the feeling he's not used to having to admit he's wrong. I guess you don't make it to 'head of security' at Google by having a little humility but his responses are really not very encouraging.

Re: Chrome's insane password security strategy

#240
post #205
post #98

Earlier quoted context omitted.

Nobody doubts that adding a master password will stop nobody who knows what they are doing. If someone has access to your computer and wants to do damage, they have full access to do it. However, keep in mind 'open door' syndrome. A crime of opportunity is very different than one of bad intentions. Leave a car unlocked with a $20 bill on the seat and you might find that $20 gone when you return. Now, if you lock the…

A potentially honest person might open a door and take something I actually don't think this is the case. An honest person would not open a car door if they saw a note in the car. Sure crooks and theives would, but honest people don.t As a counter-example, just look at what happens sometimes when you lose your phone or wallet. Oftentimes you get it back. A lot of people are honest.

Sure, but the number of people who would take it is greater than the number of people who will actively take it from your pocket, or from your locked house. A lot of people are honest does not exclude the fact that people can be opportunistic.
Post reply on HN