Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

281–290 of 315 posts

Re: Chrome's insane password security strategy

#281
post #110

Earlier quoted context omitted.

"Today, go up to somebody non-technical. Ask to borrow their computer. Visit chrome://settings/passwords and click “show” on a few of the rows. See what they have to say." Someone that does that to me would not get a punch in the nose, but that is certainly what they would deserve.

I suppose it's a pretty in-your-face way of showing you. But it would certainly get the message across. It'd be a bit of a shock, right?

I don't store any passwords in Chrome.

Regardless, what you suggest is an enormous invasion of privacy.

How about a, "Did you know that within 30 seconds, I can see all your passwords?"

Re: Chrome's insane password security strategy

#282

Earlier quoted context omitted.

Novice? I'm sorry, but whether I'm a novice has absolutely nothing to do with this. What I'm proposing is that you just don't show our passwords, all in one window, in plain text. I agree that this won't solve the problem, but would be a good first step. And I don't see how that would be dangerous. Alternatively, Chrome should make this more obvious so that users don't make assumptions about its security. How on eart…

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

> It matters that you don't seem to understand the threat model here.

Respectfully, a fairly common real world circumstance under which this is exactly the wrong choice was described, then ignored.

In response we got "you don't get it, we're staying where we are."

Is it possible that the reason people think you're doing the wrong thing is that you have made literally no attempt whatsoever to explain why you're flying against the best practices everyone else uses?

Saying "we have data" doesn't count, because we didn't see it, and everyone says that while justifying obviously incorrect stuff. I've had people mail my password back to me plaintext then insist that because they're (random important sounding thing) I should just trust their judgment.

And yes, this includes directors of security at first class software organizations with backgrounds in research security and the CIA.

Even if it turned out that you were correct, your current standoffish non-explanation is directly and severely undermining our trust in you. Do you just not care?

Sometimes you're a lot better off explaining than saying "you're too naive to understand."

.

> I've enumerated this multiple times now

Where?

.

> so I'm not sure how else to explain it

You give the very strong impression that you believe that saying "you're an amateur and we have data" is a kind of an explanation.

.

> The simple fact is that you need to lock your user account

"The simple fact is that you need to secure your server, and if you don't do that it doesn't matter that you salt and hash your passwords, and if you do do that then you don't need to salt and hash your passwords."

Yes, that's cute, LinkedIn. Back here in the real world, multiple layers of redundant, superficially weak, superficially unnecessary security have actual productive results.

.

> nothing else really matters because it's all just theater

The only theater I see here is "I've enumerated this and I don't know how else to explain it."

Unless you're talking about some other site, you haven't explained it at all, and what you're really saying is "I don't know how to explain it."

Maybe hire a communications person. You're making what appear to be by all basic security books and protocols dire security errors, then saying "I have data to support this decision and you're too dumb to understand what's going on."

Really?

Try us, sir. Closing the door in our faces is not a form of doing a good job here. If you're going to take liberties with our data, please be willing to give at least one good faith attempt to explain yourself. It's not a lot to ask.

.

> won't actually stop anyone willing to invest minimal effort.

I think you've confused wanting to stop blackhats with wanting to stop real world situations.

An angry significant other can pull this off. You're not just opening the door; you're opening it ridiculously wide, to the point that the average non-technical user can figure out how to penetrate your "security."

And then you're justifying it in terms of not wanting, through an unknown mechanism, to justify bad behavior, by leaving a vulnerability few technical people know about in place.

I just don't know how to respond to this.

Please share the data you keep talking about. The reason you don't know how to explain this better is that you haven't even begun to try.

Saying "I'm right and you're an outsider" isn't an explanation. It's a dodge.

Re: Chrome's insane password security strategy

#283

Earlier quoted context omitted.

Ha... The people complaining really are novices, looking for something to get outraged over. Every operating system allows multiple user accounts. I recommend people start learning how to use them.

I'm not a novice, but I would prefer that it wasn't trivial for a novice to access my passwords if I'm away from the keyboard for 30 seconds. A novice is going to have not a single clue of what to do with a console, but they can get at passwords in plaintext with four clicks with Chrome. No other browser makes it this easy to get at passwords in plaintext.

> No other browser makes it this easy to get at passwords in plaintext.

In Firefox you can go to preferences, security, and saved passwords. And News Flash: If you leave your wallet unattended for 30 seconds, someone could take your money. I guess wallet makers should include a warning too?

Re: Chrome's insane password security strategy

#284
post #223

Earlier quoted context omitted.

So Chrome should not allow passwords to be read without the system Keychain password. There is no technical reason it can't do this. Safari does this if you want to view passwords. Chrome makes passwords casually available, this is unlike Safari and unlike the Keychain. So either Chrome informs the user of that behaviour or it stops doing it. What it is doing now is very poorly designed behaviour. I am surprised that…

There is no technical reason it can't do this. Not all OSes have a "Keychain".

So do it on the ones that have this feature. Try to find equivalents on others.

Re: Chrome's insane password security strategy

#285
post #258

Earlier quoted context omitted.

Too bad every other browser works the same way...

They don't.

Yeah they do. In Firefox go to preferences, security, and saved passwords. I don't know about Safari or Internet Explorer because they're shit and I don't use them.

Re: Chrome's insane password security strategy

#286

Earlier quoted context omitted.

I wholeheartedly disagree with several of the points you make here, and I think you're more or less ‘passing the buck’ on something which is most definitely your responsibility to take good care with. On OS X, once you save a password using Safari, it is added to your login keychain. In order to then see that password* you must enter your login password again, be that via Safari's preferences dialog or the Keychain A…

True, chrome circumvents safari's password security by merely querying the keychain without prompting for a password. What stops anything(or anyone) else from doing it? Absolutely nothing. You've fallen into exactly the trap they wanted to avoid. You assumed Safari's password security mechanism was more secure than it is. If chrome can access it without a password prompt, I can too. In fact, there's probably some nic…

And you have completely missed the point here.

It requires a stronger level of intent for someone to dump my Keychain passwords than it does for someone to browse my Chrome passwords.

This concerns me. I have friends that I would not trust around my computer now because I know that going to chrome://settings/passwords is too tempting for them. But I trust them not to maliciously or actively attempt to subvert the security on my computer.

Re: Chrome's insane password security strategy

#288

Earlier quoted context omitted.

I'm not a novice, but I would prefer that it wasn't trivial for a novice to access my passwords if I'm away from the keyboard for 30 seconds. A novice is going to have not a single clue of what to do with a console, but they can get at passwords in plaintext with four clicks with Chrome. No other browser makes it this easy to get at passwords in plaintext.

> No other browser makes it this easy to get at passwords in plaintext. In Firefox you can go to preferences, security, and saved passwords. And News Flash: If you leave your wallet unattended for 30 seconds, someone could take your money. I guess wallet makers should include a warning too?

> In Firefox you can go to preferences, security, and saved passwords.

Incorrect if you set a master password, which Firefox allows you to do and is the reason why everyone's saying 'wtf, chrome?' and leaving firefox alone.

Re: Chrome's insane password security strategy

#289

Earlier quoted context omitted.

True, chrome circumvents safari's password security by merely querying the keychain without prompting for a password. What stops anything(or anyone) else from doing it? Absolutely nothing. You've fallen into exactly the trap they wanted to avoid. You assumed Safari's password security mechanism was more secure than it is. If chrome can access it without a password prompt, I can too. In fact, there's probably some nic…

There are skeleton keys and lockpicks to open any lock on any door, so am I giving myself a false sense of security by locking my door when I leave for work? Sometimes just having basic security that keeps a casual attempt from opening my door / accessing my password from succeeding is enough.

When you locked your door when you left for work, did you leave the key taped to the door in an unsealed envelope labeled "keys"?

Re: Chrome's insane password security strategy

#290
post #181

Earlier quoted context omitted.

"My point here is that there is little to no value" Personally speaking I've had plenty of occasions where I've logged into a site and saved the password then later Chrome doesn't recognise where to put the credentials on another page on the site (e.g. a header login vs a separate login page) - In those cases I'd rather just look to see what the password is and re-enter it than go through a password reset process.

Someone who can access your computer, unlocked, can login to your Facebook account (the password is saved), change the password, verify the email, re-save the new password, and it's just as easily "game over". You would never know what happened. Justin is absolutely right. His group is doing users a service by making these things more transparent. Folks who make exceptions based on this "security through obscurity" m…

Surely you see the difference between someone copying all of your passwords without your knowledge, and someone resetting your password for a single website that you would immediately notice when you check your email? They are two completely different types of attacks.
Post reply on HN