Earlier quoted context omitted.
Justin Schuh had a nice capsule summary of some available techniques for compromising logins: https://news.ycombinator.com/item?id=6166731 - dump all your session cookies - grab your history - install malicious extension to intercept all your browsing activity - install OS user account level monitoring software The last one could plausibly work, in combination with "grab a copy of the encrypted 1Password key file", t…
None of these are comparable to having a full-featured, user friendly GUI to grab all your passwords accessible with a simple "chrome://settings/passwords".
Google Chrome security flaw offers unrestricted password access
51–60 of 95 posts
Re: Google Chrome security flaw offers unrestricted password access
#52Earlier quoted context omitted.
I am unsure why Chrome does not ask for the master password when the user attempts to reveal the plaintext for a password. Safari does this and it works. This is a big deal because it makes reading passwords easy to do in seconds, and easy to do inconspicuously. If you were to modify the DOM to unmask passwords it would take longer, and it's not something you can do while a co-worker or friend lends you their laptop…
It does not work. It is a cosmetic security feature. If you don't log out, the next unauthorized user owns your account. You obviously know that. You're talking about a security feature based entirely off the incompetence of attackers. Why not also recommend that Chrome "Base64 encrypt" passwords? That will stop approximately the same set of attackers as the lack of a master password feature will.
Security is about far more than preventing determined, malicious attackers. It is also about being able to use your computer in a work or family environment with a reasonable expectation that your privacy will be maintained without explicit effort on your part.
You call them "attackers" but that is not who we are discussing. We are talking about people being able to casually browse your saved passwords, perhaps without even the intent to attack (maybe they just want to see what your passwords are).
Nor is this about the "incompetence of attackers." As soon as you add an extra step — such as requiring a master password to show a particular instance of a saved password — you increase the breach of trust required for a friend to violate your privacy. And it's not simply whether you trust someone or you don't, there are levels of trust between friends.
I have some friends that I would trust not to attempt to defeat my security, but I would not trust them not to casually browse my passwords. In this instance I would be safe with Safari but not with Chrome. See the difference? Chrome could easily implement Safari's solution for this and be better for it. Why defend the inferior design?
Re: Google Chrome security flaw offers unrestricted password access
#53Earlier quoted context omitted.
It does not work. It is a cosmetic security feature. If you don't log out, the next unauthorized user owns your account. You obviously know that. You're talking about a security feature based entirely off the incompetence of attackers. Why not also recommend that Chrome "Base64 encrypt" passwords? That will stop approximately the same set of attackers as the lack of a master password feature will.
It does work . Security is about far more than preventing determined, malicious attackers. It is also about being able to use your computer in a work or family environment with a reasonable expectation that your privacy will be maintained without explicit effort on your part. You call them "attackers" but that is not who we are discussing. We are talking about people being able to casually browse your saved passwords…
Security is measured in dollars; it is about the cost you confront your adversary with. Chrome has sunk many millions of dollars into blunting attacks that cost 6, 7, sometimes 8 figures. You're up in arms about a security measure that would add pennies (if that) of attacker cost. Justin and his team (rightly) observe that in return for the pennies of extra effort the feature you're demanding would add, they also incur a real risk that users will feel safer leaving their accounts unlocked. As you've already acknowledged repeatedly, if they do that, it costs pennies to get all their passwords.
There are all sorts of stupid extra steps you can add to make things harder for computer-illiterate attackers to compromise your accounts. Like I said, you could also Base64-encrypt the passwords. Or ROT14 them. Or Base64 and ROT14 them. How about you turn that into a round function and write the Base64+ROT14 Feistel network? That'll surely dissuade someone, somewhere from capturing passwords.
You will no doubt be able to come up with a 4 paragraph response to this comment. In ~20 years, I've never been able to deliver a killing blow in this stupid debate.
Re: Google Chrome security flaw offers unrestricted password access
#54Earlier quoted context omitted.
It does not work. It is a cosmetic security feature. If you don't log out, the next unauthorized user owns your account. You obviously know that. You're talking about a security feature based entirely off the incompetence of attackers. Why not also recommend that Chrome "Base64 encrypt" passwords? That will stop approximately the same set of attackers as the lack of a master password feature will.
It does work . Security is about far more than preventing determined, malicious attackers. It is also about being able to use your computer in a work or family environment with a reasonable expectation that your privacy will be maintained without explicit effort on your part. You call them "attackers" but that is not who we are discussing. We are talking about people being able to casually browse your saved passwords…
Re: Google Chrome security flaw offers unrestricted password access
#55This is embarrassing. What The Guardian (and, earlier, HN) is describing simply isn't a security flaw; rather, HN appears to have had a mild temper tantrum over the lack of a cosmetic "security" feature that, had Chrome implemented it, could have just as easily led to another temper tantrum over how easy it is to bypass.
* An FBI warning, like they have on DVDs, explaining the penalties for stealing user passwords.
* Automatically generate word-search puzzles like on the backs of chain restaurant kids menus, so that 5 year olds will have a harder time recovering passwords.
* Since most of the "attackers" the master password would block are probably senior citizens, typeset the passwords in a 7 point font.
* Since all of the "attackers" who would be thwarted by a Chrome master password are computer illiterate, make users answer a basic computer literacy quiz before showing them the password. You should have to be able to explain the difference between a library function and a system call when you push the "reveal password" button.
Note to The Guardian: I have at least 10 more similar "major security flaws" in Chrome (I gave up some more, like the red-green colorblind attacker countermeasure, on Twitter --- but I assure you I have 10 more) that I'm willing to disclose to you, and I assure you that you'll be able to find someone else on the Internet to give you quotes for your article about how terrible it is that Chrome has those flaws.
Re: Google Chrome security flaw offers unrestricted password access
#56Earlier quoted context omitted.
If Chrome was concerned about your sense of security it would inform you that all your saved passwords are clearly readable in plaintext at chrome://settings/passwords. It would do this each time it saved a password. It does not do this because you would be less likely to trust Chrome with your passwords if it did that. So Chrome wants you to feel secure and give you convenience. Either it makes some attempt to preve…
To rmc: > And that's the logic behind Clippy. No, it absolutely is not. Chrome already asks and informs you that it is saving your password. It asks each time it saves a password. It already does this . It would simply be an additional line of information in a step that you already have to confirm by clicking "Ok".
Re: Google Chrome security flaw offers unrestricted password access
#57This is embarrassing. What The Guardian (and, earlier, HN) is describing simply isn't a security flaw; rather, HN appears to have had a mild temper tantrum over the lack of a cosmetic "security" feature that, had Chrome implemented it, could have just as easily led to another temper tantrum over how easy it is to bypass.
It is a security flaw, and a big one. The only embarrassing thing here is Google's employees attempts at downplaying this. And please explain how to bypass Safari password manager, or 1Password, or any password manager with a master password, if you believe it's only a cosmetic feature.
Re: Google Chrome security flaw offers unrestricted password access
#58Earlier quoted context omitted.
It is far more likely I am using your machine with you, and then you walk out for 20 seconds to get a glass of water. You are presuming a specific environment and an attack specific to that environment. At first glance, it may look like adding the extra complexity of a password through the obvious user-interface path improves security. But that assumes there are no costs. In this case the cost is a false sense of sec…
If Chrome was concerned about your sense of security it would inform you that all your saved passwords are clearly readable in plaintext at chrome://settings/passwords. It would do this each time it saved a password. It does not do this because you would be less likely to trust Chrome with your passwords if it did that. So Chrome wants you to feel secure and give you convenience. Either it makes some attempt to preve…
Not everything is black magic and dark arts.
Re: Google Chrome security flaw offers unrestricted password access
#59People can also browse My Documents if they're logged in to my account. Microsoft should get this bug fixed asap.
Re: Google Chrome security flaw offers unrestricted password access
#60Earlier quoted context omitted.
It is far more likely I am using your machine with you, and then you walk out for 20 seconds to get a glass of water. You are presuming a specific environment and an attack specific to that environment. At first glance, it may look like adding the extra complexity of a password through the obvious user-interface path improves security. But that assumes there are no costs. In this case the cost is a false sense of sec…
If Chrome was concerned about your sense of security it would inform you that all your saved passwords are clearly readable in plaintext at chrome://settings/passwords. It would do this each time it saved a password. It does not do this because you would be less likely to trust Chrome with your passwords if it did that. So Chrome wants you to feel secure and give you convenience. Either it makes some attempt to preve…