Earlier quoted context omitted.
It is a security flaw, and a big one. The only embarrassing thing here is Google's employees attempts at downplaying this. And please explain how to bypass Safari password manager, or 1Password, or any password manager with a master password, if you believe it's only a cosmetic feature.
You bypass a password manager the same way you bypass Chrome. Just open it. If someone left the PC unlocked, there is a good chance the password manager is unlocked too.
Google Chrome security flaw offers unrestricted password access
61–70 of 95 posts
Re: Google Chrome security flaw offers unrestricted password access
#62Earlier quoted context omitted.
It does work . Security is about far more than preventing determined, malicious attackers. It is also about being able to use your computer in a work or family environment with a reasonable expectation that your privacy will be maintained without explicit effort on your part. You call them "attackers" but that is not who we are discussing. We are talking about people being able to casually browse your saved passwords…
I'm sorry, but I feel like I've had this pointless, silly debate my whole career, starting with comp.security.unix, continuing through my brief time working with OpenBSD and 90's Bugtraq, and through about a decade of helping startups with software security, and I've lost a lot of my patience for it. Security is measured in dollars; it is about the cost you confront your adversary with. Chrome has sunk many millions…
Re: Google Chrome security flaw offers unrestricted password access
#63Earlier quoted context omitted.
It is a security flaw, and a big one. The only embarrassing thing here is Google's employees attempts at downplaying this. And please explain how to bypass Safari password manager, or 1Password, or any password manager with a master password, if you believe it's only a cosmetic feature.
You bypass a password manager the same way you bypass Chrome. Just open it. If someone left the PC unlocked, there is a good chance the password manager is unlocked too.
Re: Google Chrome security flaw offers unrestricted password access
#64Earlier quoted context omitted.
You bypass a password manager the same way you bypass Chrome. Just open it. If someone left the PC unlocked, there is a good chance the password manager is unlocked too.
Nope, that's not true. Anyway, I'm done with this discussion. Google fanboys can keep using Chrome and trying to defend this bullshit, I don't care. Personally I'm done with Chrome until they fix this.
Re: Google Chrome security flaw offers unrestricted password access
#65Earlier quoted context omitted.
Exactly. Comparing that javascript with the Chrome situation is just ridiculous. It seems people here are too narrow-minded to understand that even my mother could get a list of all the passwords stored in a computer in 10 seconds.
"Even my mother"? So what? Both Firefox and Chrome are, when left on an unlocked user account, completely exposed to the scariest classes of attackers. But Firefox has taken a cosmetic step to minimize its exposure to the least scary class of attackers. Why bother?
Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attackers to absolutely everyone.
Re: Google Chrome security flaw offers unrestricted password access
#66Earlier quoted context omitted.
"Even my mother"? So what? Both Firefox and Chrome are, when left on an unlocked user account, completely exposed to the scariest classes of attackers. But Firefox has taken a cosmetic step to minimize its exposure to the least scary class of attackers. Why bother?
Because the 'least scary class of attackers' represent the vast majority of potential attackers. This feature makes it trivial for a user error (not locking your desktop) to leave your passwords immediately visible to anyone that walks by. Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attac…
Re: Google Chrome security flaw offers unrestricted password access
#67People can also browse My Documents if they're logged in to my account. Microsoft should get this bug fixed asap.
Chrome should ask for the master Keychain password when you attempt to unmask a password. It does not do this, and it could easily do this (like Safari does). So it's a flaw. Alternatively Chrome should inform the user that saved passwords are easily readable in plaintext, so that users will not trust it as much. It does not do this either. There's a difference between browsing someone's private documents and having…
Well, except that you can just dump the passwords from Keychain without the master password.
Re: Google Chrome security flaw offers unrestricted password access
#68Isn't it a known fact that, when asked, browsers store passwords in plaintext? Why would anyone choose to let the browser 'remember their password' anyway?
Re: Google Chrome security flaw offers unrestricted password access
#69Earlier quoted context omitted.
Because the 'least scary class of attackers' represent the vast majority of potential attackers. This feature makes it trivial for a user error (not locking your desktop) to leave your passwords immediately visible to anyone that walks by. Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attac…
If you leave your machine unlocked, you have made it trivial for someone to steal your secrets no matter what Chrome does.
With this feature, it's trivial for absolutely anyone to steal my secrets in seconds.
Without this feature, the time-to-compromise goes up, as does the technical knowledge required. The degree-of-difficulty (which, yes, is still low), goes up.
It is cosmetic, but INTERFACE MATTERS. If you don't want people doing something, don't have a feature that makes it trivially easy.
Hell, if chrome devs really aren't going to do anything at all about this, then a better solution here would be to bring the button to the FRONT of the interface. 'View All Passwords', right beside the 'back' button, navigates you to a raw txt file of websites and passwords. Then, at least, there would be no excuse, no naive assumption that chrome is doing SOMETHING to protect your passwords.
Re: Google Chrome security flaw offers unrestricted password access
#70Earlier quoted context omitted.
If you leave your machine unlocked, you have made it trivial for someone to steal your secrets no matter what Chrome does.
Degree of difficulty matters. The technical ability of the attacker matters . With this feature, it's trivial for absolutely anyone to steal my secrets in seconds. Without this feature, the time-to-compromise goes up, as does the technical knowledge required. The degree-of-difficulty (which, yes, is still low), goes up. It is cosmetic, but INTERFACE MATTERS. If you don't want people doing something, don't have a feat…
What we disagree on is the specific degree in this case. You think it's significant. I know it's not. Chrome's security design is denominated in thousands of dollars. This is a penny feature, and one with potential liabilities; it could cost more than it benefits.