Live data from Hacker News

Google Chrome security flaw offers unrestricted password access

theguardian.com

61–70 of 95 posts

Re: Google Chrome security flaw offers unrestricted password access

#61

Earlier quoted context omitted.

It is a security flaw, and a big one. The only embarrassing thing here is Google's employees attempts at downplaying this. And please explain how to bypass Safari password manager, or 1Password, or any password manager with a master password, if you believe it's only a cosmetic feature.

You bypass a password manager the same way you bypass Chrome. Just open it. If someone left the PC unlocked, there is a good chance the password manager is unlocked too.

Nope, that's not true. Anyway, I'm done with this discussion. Google fanboys can keep using Chrome and trying to defend this bullshit, I don't care. Personally I'm done with Chrome until they fix this.

Re: Google Chrome security flaw offers unrestricted password access

#62
post #53

Earlier quoted context omitted.

It does work . Security is about far more than preventing determined, malicious attackers. It is also about being able to use your computer in a work or family environment with a reasonable expectation that your privacy will be maintained without explicit effort on your part. You call them "attackers" but that is not who we are discussing. We are talking about people being able to casually browse your saved passwords…

I'm sorry, but I feel like I've had this pointless, silly debate my whole career, starting with comp.security.unix, continuing through my brief time working with OpenBSD and 90's Bugtraq, and through about a decade of helping startups with software security, and I've lost a lot of my patience for it. Security is measured in dollars; it is about the cost you confront your adversary with. Chrome has sunk many millions…

What are considered stupid extra steps by some, others may consider to be deciding factors for using a product or not. The user experience in this case requires a fix regardless of what you may consider a penny solution value. Ownership of the UE often means choosing penny solutions along the way.

Re: Google Chrome security flaw offers unrestricted password access

#63

Earlier quoted context omitted.

It is a security flaw, and a big one. The only embarrassing thing here is Google's employees attempts at downplaying this. And please explain how to bypass Safari password manager, or 1Password, or any password manager with a master password, if you believe it's only a cosmetic feature.

You bypass a password manager the same way you bypass Chrome. Just open it. If someone left the PC unlocked, there is a good chance the password manager is unlocked too.

As far as I'm used too, you have to enter a password still for a PW manager.

Re: Google Chrome security flaw offers unrestricted password access

#64

Earlier quoted context omitted.

You bypass a password manager the same way you bypass Chrome. Just open it. If someone left the PC unlocked, there is a good chance the password manager is unlocked too.

Nope, that's not true. Anyway, I'm done with this discussion. Google fanboys can keep using Chrome and trying to defend this bullshit, I don't care. Personally I'm done with Chrome until they fix this.

How you know it's a serious, well-thought-out, easily supportable position being argued for is that it's capped off with the accusation that people who disagree are "Google fanboys".

Re: Google Chrome security flaw offers unrestricted password access

#65
post #50

Earlier quoted context omitted.

Exactly. Comparing that javascript with the Chrome situation is just ridiculous. It seems people here are too narrow-minded to understand that even my mother could get a list of all the passwords stored in a computer in 10 seconds.

"Even my mother"? So what? Both Firefox and Chrome are, when left on an unlocked user account, completely exposed to the scariest classes of attackers. But Firefox has taken a cosmetic step to minimize its exposure to the least scary class of attackers. Why bother?

Because the 'least scary class of attackers' represent the vast majority of potential attackers. This feature makes it trivial for a user error (not locking your desktop) to leave your passwords immediately visible to anyone that walks by.

Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attackers to absolutely everyone.

Re: Google Chrome security flaw offers unrestricted password access

#66
post #50

Earlier quoted context omitted.

"Even my mother"? So what? Both Firefox and Chrome are, when left on an unlocked user account, completely exposed to the scariest classes of attackers. But Firefox has taken a cosmetic step to minimize its exposure to the least scary class of attackers. Why bother?

Because the 'least scary class of attackers' represent the vast majority of potential attackers. This feature makes it trivial for a user error (not locking your desktop) to leave your passwords immediately visible to anyone that walks by. Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attac…

If you leave your machine unlocked, you have made it trivial for someone to steal your secrets no matter what Chrome does.

Re: Google Chrome security flaw offers unrestricted password access

#67
post #17

People can also browse My Documents if they're logged in to my account. Microsoft should get this bug fixed asap.

Chrome should ask for the master Keychain password when you attempt to unmask a password. It does not do this, and it could easily do this (like Safari does). So it's a flaw. Alternatively Chrome should inform the user that saved passwords are easily readable in plaintext, so that users will not trust it as much. It does not do this either. There's a difference between browsing someone's private documents and having…

> Chrome should ask for the master Keychain password when you attempt to unmask a password. It does not do this, and it could easily do this (like Safari does).

Well, except that you can just dump the passwords from Keychain without the master password.

https://news.ycombinator.com/item?id=4518873

Re: Google Chrome security flaw offers unrestricted password access

#68

Isn't it a known fact that, when asked, browsers store passwords in plaintext? Why would anyone choose to let the browser 'remember their password' anyway?

I think this is the real debate. Since when did Browsers get into the account/password storing industry? Isn't this why we have browser extensions in the first place?

Re: Google Chrome security flaw offers unrestricted password access

#69
post #66

Earlier quoted context omitted.

Because the 'least scary class of attackers' represent the vast majority of potential attackers. This feature makes it trivial for a user error (not locking your desktop) to leave your passwords immediately visible to anyone that walks by. Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attac…

If you leave your machine unlocked, you have made it trivial for someone to steal your secrets no matter what Chrome does.

Degree of difficulty matters. The technical ability of the attacker matters.

With this feature, it's trivial for absolutely anyone to steal my secrets in seconds.

Without this feature, the time-to-compromise goes up, as does the technical knowledge required. The degree-of-difficulty (which, yes, is still low), goes up.

It is cosmetic, but INTERFACE MATTERS. If you don't want people doing something, don't have a feature that makes it trivially easy.

Hell, if chrome devs really aren't going to do anything at all about this, then a better solution here would be to bring the button to the FRONT of the interface. 'View All Passwords', right beside the 'back' button, navigates you to a raw txt file of websites and passwords. Then, at least, there would be no excuse, no naive assumption that chrome is doing SOMETHING to protect your passwords.

Re: Google Chrome security flaw offers unrestricted password access

#70
post #66

Earlier quoted context omitted.

If you leave your machine unlocked, you have made it trivial for someone to steal your secrets no matter what Chrome does.

Degree of difficulty matters. The technical ability of the attacker matters . With this feature, it's trivial for absolutely anyone to steal my secrets in seconds. Without this feature, the time-to-compromise goes up, as does the technical knowledge required. The degree-of-difficulty (which, yes, is still low), goes up. It is cosmetic, but INTERFACE MATTERS. If you don't want people doing something, don't have a feat…

Yes, degree of difficulty matters. We don't disagree on that. It's the fundamental rule of security.

What we disagree on is the specific degree in this case. You think it's significant. I know it's not. Chrome's security design is denominated in thousands of dollars. This is a penny feature, and one with potential liabilities; it could cost more than it benefits.

Post reply on HN