Live data from Hacker News

Chrome's insane password security strategy

blog.elliottkember.com

291–300 of 315 posts

Re: Chrome's insane password security strategy

#291

Earlier quoted context omitted.

Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.

Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…

Dear Justin and other Chrome Devs

I have been waiting for so long to bash you on this point. And now when it comes, I'm at an utter loss for words.

What would it take to open your eyes to the severity of the matter? Are you really intending to let this slide away? Putting a master-password or some other level of security over the stored passwords is not such a big deal either that you would want to so actively evade them.

Are you counting on insecure stored passwords as a "differentiating feature" from Firefox?

I had stayed off Chrome for a long time due to the same reason: "No security for my stored passwords". But then I switched because Chrome became very fast and I used LastPass for storing passwords.

I'm telling you this because I'll not shy away from recommending Firefox or even IE10 to other people when they are looking for a browser, because hey, Chrome lets other people see your passwords, just like that.

Re: Chrome's insane password security strategy

#292
post #109

Earlier quoted context omitted.

If I have access to your browser, I can get your credentials for Amazon by just going to Amazon.com . Either you already have a session open, and then I can do what I want (including changing your password), or the browser (or your password manager) is going to fill in the password automatically, and with a trivial knowledge of how the browser works I can copy the password. I use LastPass, and it is possible to set i…

My house has a front door which can be locked. I often leave it unlocked when I am out in the yard (and thus need access through the door on a minute-by-minute basis) or when I have guests over. I side my house I have safes, medicine cabinets and a gun rack. Those things are locked all the time, and I only unlock the cabinet when I need to use the items inside the secure container. So, too, I have a use account login…

Thanks for the precise and lucid argument.

I'm so angry right now that I can't even string together my sentences properly :)

Re: Chrome's insane password security strategy

#293
post #258

Earlier quoted context omitted.

They don't.

Yeah they do. In Firefox go to preferences, security, and saved passwords. I don't know about Safari or Internet Explorer because they're shit and I don't use them.

Well, Firefox does also offer a "Master Password" if you haven't notice.

Re: Chrome's insane password security strategy

#294
post #210
post #187

Earlier quoted context omitted.

> Why is it such a problem to ask the user to enter their account password before viewing this prefpane? You've not provided a valid argument against this. Most users do not have to enter their password when their OS boots, and thus won't know what it is. So offering it in Chrome is an inconvenience for most users, but adds no extra security. Once an attacker has physical access and can run Chrome browser it's game o…

Again, missing the point. Both your average attacker and average user have as much technical knowledge as a daffodil, which means even the most trivial barrier would be effective. As to users who don't set a password - never make the passwords visible.

In that case the most trivial barrier is to lock the screen when you're away from your machine, or to set a guest account for when you lend the machine to someone else.

Re: Chrome's insane password security strategy

#295

Earlier quoted context omitted.

True, chrome circumvents safari's password security by merely querying the keychain without prompting for a password. What stops anything(or anyone) else from doing it? Absolutely nothing. You've fallen into exactly the trap they wanted to avoid. You assumed Safari's password security mechanism was more secure than it is. If chrome can access it without a password prompt, I can too. In fact, there's probably some nic…

And you have completely missed the point here. It requires a stronger level of intent for someone to dump my Keychain passwords than it does for someone to browse my Chrome passwords. This concerns me. I have friends that I would not trust around my computer now because I know that going to chrome://settings/passwords is too tempting for them. But I trust them not to maliciously or actively attempt to subvert the sec…

And you missed the point also. Lock your computer when you're not at it. Like any responsible user. Problem solved.

It's not hard to understand where the boundaries are. Also, it's actually up to Apple to fix the broken thing, not Chrome. There should be a settings in the preferences of the keychain to require a password even if it's been unlocked before (or however that works. I don't Mac)

Re: Chrome's insane password security strategy

#296
post #149

Earlier quoted context omitted.

If chrome ever removes that setting, I will make chromereveal.com with one-click idiot-proof password dumping tool, and step-by step instructions. So hiding that button will not make it harder for your friends. Just logout and give them guest access...geez.

So you log out of your computer every time you give your computer to your wife?

For the sake of argument, I'll answer this with s/wife/friends/

Yes, if I'm not besides it, I will switch user accounts. And if I walk away from my computer for a bit, I lock it (except when there are no untrusted people around, like at home). I have "Lock Screen" bound to Ctrl-Alt-L, so it's trivial to do.

Re: Chrome's insane password security strategy

#297
post #2

I just did a little digging just by visiting some sites I've saved passwords for (in Safari) using Chrome. Chrome (on OS X at least) doesn't seem to actually store them in plaintext per-se, but what it does do is equally creepy. When you visit a site (i used twitter.com for my test) Chrome will attempt to access any Keychain items matching that location - you should get the stanrdard Keychain Access dialog prompting…

I realize this story is off the front page by now, but I have some immediately recent observations to add that indicate this duplicating activity is probably a bug.

tl;dr - This duplication activity is a bug. Chrome also likes to remember incorrect passwords in these duplicate entries, thwarting attempts at usability on many of the AD-credentialed sites I visit. I have not tested this stuff with non-HTTP, non-AD authentication, but I would expect similar behavior. I've provided Google with details.

I'm a Mac developer for my company. I use a Mac running OS X. I use Chrome as my default browser. The company network has Windows servers and our network credentials are handled by Active Directory. For this test, I closed Chrome and deleted the passwords (there were three listed) and reopened Chrome.

I open TFS in a new tab, I'm prompted for my AD credentials. I enter them, log in successfully, and Chrome asks if I it should save this password for my. I answer 'Yes.' I look back at the keychain and bam there are two entries.

When I changed my AD password on Monday, Chrome needed the new password. I enter it in the prompt, but Chrome changes the password in only one of these keychain entries. Deleting the incorrect password entry while Chrome is running did no good - it was recreated by Chrome with the wrong password. Then on subsequent starts, I don't know which password Chrome is trying to use, I click 'login' without typing a password[1] and it fails. So I continually have to type my password anyway, unless I visit the keychain and remove the offending password.

[1] The prompts for AD credentials annoy me; I'm presented with the login prompt every time I open this page; can't the browser just submit the password and only prompt me if it fails?

Re: Chrome's insane password security strategy

#298
I honestly can't believe people on this board are arguing to have Chrome remove the button to show these passwords, the passwords you knowingly saved into your computer and are obviously available to anybody you "lend" your signed-in computer to. Have your own sense of security and take some responsibility. You make your own decisions for sake of convenience, now you need to accept the ramifications.

Re: Chrome's insane password security strategy

#299

Earlier quoted context omitted.

It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…

Whoa, whoa, whoa. Let's all take a step back and try to see the forest for the trees. I read Mr. Kember's article (as well as numerous others linking to it around the web today) and what I read made me concerned enough to delete all of my passwords from Chrome until I understand a little more about the issue. justinschuh seems to have a deep technical understanding of programming and program security so I will defer…

maybe he wanted to say that malevolent people have always enough skills to stole your password, even if you have a master password like firefox.

Re: Chrome's insane password security strategy

#300

Earlier quoted context omitted.

> No other browser makes it this easy to get at passwords in plaintext. In Firefox you can go to preferences, security, and saved passwords. And News Flash: If you leave your wallet unattended for 30 seconds, someone could take your money. I guess wallet makers should include a warning too?

> In Firefox you can go to preferences, security, and saved passwords. Incorrect if you set a master password, which Firefox allows you to do and is the reason why everyone's saying 'wtf, chrome?' and leaving firefox alone.

IF you set a master password... But how many people do that? By the way, you can set up user profiles in Chrome.
Post reply on HN