I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…
Chrome's insane password security strategy
261–270 of 315 posts
Re: Chrome's insane password security strategy
#262Earlier quoted context omitted.
It matters that you don't seem to understand the threat model here. You think your passwords are protected somehow in other applications, but they're simply not. The fact is that they're still trivially recoverable, and if the bad guy can read them at all than he already has access to fully compromise your entire OS user account. So, you're arguing that we take measures to make users think they're safe when they've a…
Whoa, whoa, whoa. Let's all take a step back and try to see the forest for the trees. I read Mr. Kember's article (as well as numerous others linking to it around the web today) and what I read made me concerned enough to delete all of my passwords from Chrome until I understand a little more about the issue. justinschuh seems to have a deep technical understanding of programming and program security so I will defer…
As long as your password keychain is unsecured, EVERY browser does this -- it's just a matter of knowing where the passwords are stored in the browser as plaintext. If you don't want people to access your accounts, then secure them. You can't have your cake and eat it too. Either your passwords are conveniently stored in plaintext so you can login easier, or you take actions to secure your account and add a step to the login process.
Re: Chrome's insane password security strategy
#263Earlier quoted context omitted.
If I have access to your browser, I can get your credentials for Amazon by just going to Amazon.com . Either you already have a session open, and then I can do what I want (including changing your password), or the browser (or your password manager) is going to fill in the password automatically, and with a trivial knowledge of how the browser works I can copy the password. I use LastPass, and it is possible to set i…
My house has a front door which can be locked. I often leave it unlocked when I am out in the yard (and thus need access through the door on a minute-by-minute basis) or when I have guests over. I side my house I have safes, medicine cabinets and a gun rack. Those things are locked all the time, and I only unlock the cabinet when I need to use the items inside the secure container. So, too, I have a use account login…
Re: Chrome's insane password security strategy
#264Earlier quoted context omitted.
> Why is it such a problem to ask the user to enter their account password before viewing this prefpane? You've not provided a valid argument against this. Most users do not have to enter their password when their OS boots, and thus won't know what it is. So offering it in Chrome is an inconvenience for most users, but adds no extra security. Once an attacker has physical access and can run Chrome browser it's game o…
Again, missing the point. Both your average attacker and average user have as much technical knowledge as a daffodil, which means even the most trivial barrier would be effective. As to users who don't set a password - never make the passwords visible.
Re: Chrome's insane password security strategy
#265Earlier quoted context omitted.
Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.
Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…
Re: Chrome's insane password security strategy
#266I'm the Chrome browser security tech lead, so it might help if I explain our reasoning here. The only strong permission boundary for your password storage is the OS user account. So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater.…
Does it means that all these passwords are stored in my Google Account ?
Does it means that applying steps below is possible ?
1. Steal Google credentials : By using phishing or simply access the password Chrome page of an unmonitored screen (it only requires 10 seconds), 2. On a other system, use the stolen Google credentials to connect on an blank Chrome installation, 3. Open the password list page, and get access to all the passwords registered in the Google Account.
If it works, it provides a long term remote access to all the passwords stored on the targeted Google Account.
Even if the targeted user changes the stored passwords (Facebook, ...), as long as it stores them on Chrome and does not change its Google password, I can get all the password changes.
Please, tell me that I missed something, and that I am wrong ...
Re: Chrome's insane password security strategy
#267Earlier quoted context omitted.
Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.
Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…
Re: Chrome's insane password security strategy
#268Earlier quoted context omitted.
Elliottkmember is right here. Chrome's approach to this is absurd. What if you simply don't want friends, coworkers, significant others browsing your passwords? At least tell users that if they choose to save passwords in Chrome, that everyone who uses their computer, even pretty non-technical people, will be able to access those passwords. Tell them that storing their passwords in Chrome is unsafe. Justin, can you t…
Please don't invent motivations for the statements people make when you don't like what they've stated so far. If you don't want people browsing your passwords, you can't ever give them access to your user account or your unlocked desktop. That's it, that is the entire solution. Any other method of protecting the passwords is vulnerable as long as the potential attacker has physical access to the unlocked desktop. No…
Re: Chrome's insane password security strategy
#269Earlier quoted context omitted.
Soft boundaries within the user account do nothing to protect you from exactly those scenarios either. Your protection is to lock your OS user account.
Hey Justin, I'm the author. I appreciate your sentiments, but I feel like they may be out of touch with the way real people are using computers in the wild. My suggestion is to seriously re-evaluate this approach in light of the actual use-case of how people perceive these passwords. It appears as though many, many users don't expect these passwords to be visible. This is an important thing to take into consideration…
Re: Chrome's insane password security strategy
#270Earlier quoted context omitted.
If you actually _want_ someone's password and you have access to their account, there are many things you can do, all equally easy. The more interesting argument here is the "crime of convenience" - where someone didn't want the passwords, but just saw them laying around in plain sight. But that isn't actually the case in Chrome: it's like four clicks. You have to actually be trying to find them.
The point is that 4 clicks is a LOT more convenient than most people would expect. Not to mention this doesn't seem to be an oversight by the Chrome team - it seems this is 'as designed'.
Why are you more concerned about something he has to go digging through settings purposely to find, than something he is almost guaranteed to stumble across?