Live data from Hacker News

Google Chrome security flaw offers unrestricted password access

theguardian.com

91–95 of 95 posts

Re: Google Chrome security flaw offers unrestricted password access

#91
post #60

Earlier quoted context omitted.

If Chrome was concerned about your sense of security it would inform you that all your saved passwords are clearly readable in plaintext at chrome://settings/passwords. It would do this each time it saved a password. It does not do this because you would be less likely to trust Chrome with your passwords if it did that. So Chrome wants you to feel secure and give you convenience. Either it makes some attempt to preve…

When you save your passwords in Chrome, it tells you that it's saving your passwords. If you don't think that that implies that the passwords will be retrievable at a later date, I don't think you understand what the word "save" means.

Safari also tells me it is saving my passwords. Yet to explicitly unmask my passwords from the settings screen at a later date it requires my Keychain password.

They both use the word "save" to denote this functionality.

I don't think you understand why this difference in behaviour is important.

Re: Google Chrome security flaw offers unrestricted password access

#92
post #31

i don't get it. how is Chrome's handling different from Thunderbird's or Firefox's? they too have the exact same functionalities accessible to anyone sitting at the computer without extra security measures: Options > Security > Saved Passwords > Show Passwords

If you have a master password set, Firefox makes you type it in before it will show you the passwords. Chrome doesn't do that.

if... but the article mainly complained about not being obvious for "normal" people that their password can be read. i have my doubts that it would be more obvious for those people that they can (should) set a master password in firefox.

Re: Google Chrome security flaw offers unrestricted password access

#93
post #60

Earlier quoted context omitted.

When you save your passwords in Chrome, it tells you that it's saving your passwords. If you don't think that that implies that the passwords will be retrievable at a later date, I don't think you understand what the word "save" means.

Safari also tells me it is saving my passwords. Yet to explicitly unmask my passwords from the settings screen at a later date it requires my Keychain password. They both use the word "save" to denote this functionality. I don't think you understand why this difference in behaviour is important.

So do you expect the browser to prompt you for the master password each time it is about to autofill credentials on a web page?

Re: Google Chrome security flaw offers unrestricted password access

#94
post #93

Earlier quoted context omitted.

Safari also tells me it is saving my passwords. Yet to explicitly unmask my passwords from the settings screen at a later date it requires my Keychain password. They both use the word "save" to denote this functionality. I don't think you understand why this difference in behaviour is important.

So do you expect the browser to prompt you for the master password each time it is about to autofill credentials on a web page?

No, and that is because there is a significant difference between a user unmasking the password through DOM manipulation and browsing a settings page. Please realise that the former behaviour requires more malicious intent.

I expect some level of security to stop people browsing my passwords casually, which Chrome allows in its current design.

I am not talking about fending off determined attackers, I am talking about levels of trust that you place in friends and coworkers. Chrome lowers the barrier-to-access by design.

The simple fact is: there are people I would trust using my computer who would never actively try to circumvent my security to read my passwords, but I would not trust them not to take a peek at my Chrome settings page passwords.

Re: Google Chrome security flaw offers unrestricted password access

#95

Isn't it a known fact that, when asked, browsers store passwords in plaintext? Why would anyone choose to let the browser 'remember their password' anyway?

I think this is the real debate. Since when did Browsers get into the account/password storing industry? Isn't this why we have browser extensions in the first place?

True that.

The answer is also kinda obvious. It started it as a matter of convenience ("I'm too fking bored to type out my long-ass password" or "I have so many passwords, I can't be bothered to remember them all" or "LastPass? What's that?") and has remained so till date. In fact, it will continue to do so until a zero-day exploit appears that can uncover these plaintext passwords, which, judging by current events, doesn't seem too far away

Post reply on HN