Live data from Hacker News

Google Chrome security flaw offers unrestricted password access

theguardian.com

81–90 of 95 posts

Re: Google Chrome security flaw offers unrestricted password access

#81
post #53

Earlier quoted context omitted.

It does work . Security is about far more than preventing determined, malicious attackers. It is also about being able to use your computer in a work or family environment with a reasonable expectation that your privacy will be maintained without explicit effort on your part. You call them "attackers" but that is not who we are discussing. We are talking about people being able to casually browse your saved passwords…

I'm sorry, but I feel like I've had this pointless, silly debate my whole career, starting with comp.security.unix, continuing through my brief time working with OpenBSD and 90's Bugtraq, and through about a decade of helping startups with software security, and I've lost a lot of my patience for it. Security is measured in dollars; it is about the cost you confront your adversary with. Chrome has sunk many millions…

You have completely missed the point. This issue does not relate malicious attacks. It is about the intent required for a friend or co-worker to breach your trust.

Chrome lowers the barrier and makes access casual where other systems require a stronger level of intent. That's the problem. I have no idea why you are defending this behaviour.

Re: Google Chrome security flaw offers unrestricted password access

#82
post #66

Earlier quoted context omitted.

Because the 'least scary class of attackers' represent the vast majority of potential attackers. This feature makes it trivial for a user error (not locking your desktop) to leave your passwords immediately visible to anyone that walks by. Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attac…

If you leave your machine unlocked, you have made it trivial for someone to steal your secrets no matter what Chrome does.

Leaving your machine unlocked for 30 seconds versus 5 minutes is a big difference to some people. Chrome makes password access within the former time limit a more distinct possibility.

Having someone able to casually browse your passwords versus intending to attack your system and breach your trust to get them is a big difference.

Can you not see that Chrome lowers social and emotional barriers to password access by presenting them in this form? That is the concern here.

Re: Google Chrome security flaw offers unrestricted password access

#83

Earlier quoted context omitted.

To rmc: > And that's the logic behind Clippy. No, it absolutely is not. Chrome already asks and informs you that it is saving your password. It asks each time it saves a password. It already does this . It would simply be an additional line of information in a step that you already have to confirm by clicking "Ok".

Every additional "line of information" in a pop-up notice reduces the probability that any of it will be read.

Right. So the better option is to secure passwords slightly by default. I suggested the additional information for those that feel that securing passwords is "lulling users into a false sense of security".

Either you make some attempt to secure the passwords, or you let your users know that they are readable in plaintext. Don't do neither, like Chrome is doing.

Re: Google Chrome security flaw offers unrestricted password access

#84

Earlier quoted context omitted.

Chrome should ask for the master Keychain password when you attempt to unmask a password. It does not do this, and it could easily do this (like Safari does). So it's a flaw. Alternatively Chrome should inform the user that saved passwords are easily readable in plaintext, so that users will not trust it as much. It does not do this either. There's a difference between browsing someone's private documents and having…

> Chrome should ask for the master Keychain password when you attempt to unmask a password. It does not do this, and it could easily do this (like Safari does). Well, except that you can just dump the passwords from Keychain without the master password. https://news.ycombinator.com/item?id=4518873

But that is completely missing the point relating to intent.

Browsing the Chrome's password page requires far less malicious intent than finding/writing a script to dump someone's keychain passwords.

That's the main issue for me with Chrome. I know people that I wouldn't trust not to navigate to chrome://settings/passwords, yet I would trust them not to actively attempt to defeat my computer's security (no matter how feeble).

Chrome makes it easier to breach trust. A bad design.

Re: Google Chrome security flaw offers unrestricted password access

#85

Earlier quoted context omitted.

> Chrome should ask for the master Keychain password when you attempt to unmask a password. It does not do this, and it could easily do this (like Safari does). Well, except that you can just dump the passwords from Keychain without the master password. https://news.ycombinator.com/item?id=4518873

But that is completely missing the point relating to intent . Browsing the Chrome's password page requires far less malicious intent than finding/writing a script to dump someone's keychain passwords. That's the main issue for me with Chrome. I know people that I wouldn't trust not to navigate to chrome://settings/passwords, yet I would trust them not to actively attempt to defeat my computer's security (no matter ho…

> But that is completely missing the point relating to intent.

Well, yeah, I'm certainly not seeing any point there.

> Browsing the Chrome's password page requires far less malicious intent than finding/writing a script to dump someone's keychain passwords.

No, it doesn't. It might require somewhat more effort, but it doesn't require any different amount of intent.

> I know people that I wouldn't trust not to navigate to chrome://settings/passwords, yet I would trust them not to actively attempt to defeat my computer's security

Intentionally navigating to chrome://settings/passwords is no less an active attempt to defeat security than doing a command line dump of the keychain passwords is.

> Chrome makes it easier to breach trust.

Its trivially easy to breach trust in about a million different ways if you are given unsupervised accessed to an unlocked OS user account with sensitive information attached to it. Chrome does not make any significant difference to that.

Re: Google Chrome security flaw offers unrestricted password access

#86
post #53

Earlier quoted context omitted.

I'm sorry, but I feel like I've had this pointless, silly debate my whole career, starting with comp.security.unix, continuing through my brief time working with OpenBSD and 90's Bugtraq, and through about a decade of helping startups with software security, and I've lost a lot of my patience for it. Security is measured in dollars; it is about the cost you confront your adversary with. Chrome has sunk many millions…

You have completely missed the point. This issue does not relate malicious attacks. It is about the intent required for a friend or co-worker to breach your trust. Chrome lowers the barrier and makes access casual where other systems require a stronger level of intent. That's the problem. I have no idea why you are defending this behaviour .

So again: they should display an FBI warning, just like they do on DVD movies.

Re: Google Chrome security flaw offers unrestricted password access

#87

Earlier quoted context omitted.

But that is completely missing the point relating to intent . Browsing the Chrome's password page requires far less malicious intent than finding/writing a script to dump someone's keychain passwords. That's the main issue for me with Chrome. I know people that I wouldn't trust not to navigate to chrome://settings/passwords, yet I would trust them not to actively attempt to defeat my computer's security (no matter ho…

> But that is completely missing the point relating to intent. Well, yeah, I'm certainly not seeing any point there. > Browsing the Chrome's password page requires far less malicious intent than finding/writing a script to dump someone's keychain passwords. No, it doesn't. It might require somewhat more effort, but it doesn't require any different amount of intent. > I know people that I wouldn't trust not to navigat…

So you are defending the design of this system, even though it has a lower barrier-to-access than the alternative (as implemented by Safari).

> Intentionally navigating to chrome://settings/passwords is no less an active attempt to defeat security than doing a command line dump of the keychain passwords is.

I know people who would navigate to chrome://settings/passwords right in front of me as a way to annoy me — to force me to change my passwords. Their intent would be to annoy and not to attack. The fact is that you need less motivation, and less intent, to go to the password page than to deploy a script / modify the DOM / do any number of other things to get a user's passwords.

Navigating to that page is less of an active attempt to defeat security. Hell, even I feel like it's something I would try on someone's machine when I would never even consider breaching security in another way.

> Its trivially easy to breach trust in about a million different ways if you are given unsupervised accessed to an unlocked OS user account with sensitive information attached to it. Chrome does not make any significant difference to that.

I consider the difference to be significant. I want Chrome to improve its design in this area.

Either securing this page or informing the user that their passwords are readable would be a better design than what is currently implemented. Are you arguing this is not the case?

Just because you can do it a million other ways does not mean you should be fine with this way of accessing a user's private data.

Re: Google Chrome security flaw offers unrestricted password access

#88
post #86

Earlier quoted context omitted.

You have completely missed the point. This issue does not relate malicious attacks. It is about the intent required for a friend or co-worker to breach your trust. Chrome lowers the barrier and makes access casual where other systems require a stronger level of intent. That's the problem. I have no idea why you are defending this behaviour .

So again: they should display an FBI warning, just like they do on DVD movies.

Securing the password page is not remotely similar to an FBI warning on a DVD.

One requires a bit of manual effort and thought to get over for the casual user, the other becomes ignored by the casual user.

Re: Google Chrome security flaw offers unrestricted password access

#89
post #70

Earlier quoted context omitted.

Degree of difficulty matters. The technical ability of the attacker matters . With this feature, it's trivial for absolutely anyone to steal my secrets in seconds. Without this feature, the time-to-compromise goes up, as does the technical knowledge required. The degree-of-difficulty (which, yes, is still low), goes up. It is cosmetic, but INTERFACE MATTERS. If you don't want people doing something, don't have a feat…

Yes, degree of difficulty matters. We don't disagree on that. It's the fundamental rule of security. What we disagree on is the specific degree in this case. You think it's significant. I know it's not. Chrome's security design is denominated in thousands of dollars. This is a penny feature, and one with potential liabilities; it could cost more than it benefits.

Can you please explain the potential liabilities for making Chrome work the same way Safari does when attempting to reveal passwords? (I.e., ask for the Keychain password before unmasking.)

To me this would be a great solution and would improve Chrome's user experience. I am unsure why the strong argument against this.

Re: Google Chrome security flaw offers unrestricted password access

#90

Earlier quoted context omitted.

If Chrome was concerned about your sense of security it would inform you that all your saved passwords are clearly readable in plaintext at chrome://settings/passwords. It would do this each time it saved a password. It does not do this because you would be less likely to trust Chrome with your passwords if it did that. So Chrome wants you to feel secure and give you convenience. Either it makes some attempt to preve…

I've talked to my less-technical relatives who use browsers, and they've all known that saving passwords means that someone who gets access to their computer means they get access to their accounts and/or passwords. Not everything is black magic and dark arts.

I showed two developer friends at work today the ease at which I could recover their Chrome passwords. They were both surprised that they were clearly visible on the settings page.

Both have since stopped storing passwords in Chrome.

Both developers expected their Keychain password to be needed before unmasking their stored passwords. It shocked them that this was not the case.

A better fix for this would be to require the Keychain password before showing all passwords. There is no harm in doing this.

Post reply on HN