Live data from Hacker News

Google Chrome security flaw offers unrestricted password access

theguardian.com

1–10 of 95 posts

Re: Google Chrome security flaw offers unrestricted password access

#3
Same as reported here: https://news.ycombinator.com/item?id=6167331

Interesting to see the Guardian newspaper quoting someone from Hacker News.

Same is also true of Firefox - find the right path through the menu structure (different for each version) and reveal all your passwords.

Simple enough.

Re: Google Chrome security flaw offers unrestricted password access

#6
> The fact you can view the passwords means they are stored in reversible form which means that the dark coders out there will be writing a Trojan to steal that password store as we speak.

Surely they have to be reversible, or the browser wouldn't be able to use them as passwords.

Re: Google Chrome security flaw offers unrestricted password access

#7
Why is Chrome named as the "bad guy"? If anything, Chrome reveals the issue, by showing just how accessible browser-saved passwords are in the first place. Do you think that it's impossible for malware to retrieve passwords from IE, Firefox, Safari and Opera? Just how is it possible to import the passwords from these applications, then?

This is not a security flaw. Comparing browser password storage to a safe is mildly retarded.

Re: Google Chrome security flaw offers unrestricted password access

#8

Same as reported here: https://news.ycombinator.com/item?id=6167331 Interesting to see the Guardian newspaper quoting someone from Hacker News. Same is also true of Firefox - find the right path through the menu structure (different for each version) and reveal all your passwords. Simple enough.

> Interesting to see the Guardian newspaper quoting someone from Hacker News.

He isn't just some random commenter though, he is the tech lead of browser security (according to his comment, which I'm guessing The Guardian didn't actually verify :D)

Re: Google Chrome security flaw offers unrestricted password access

#10
This is embarrassing. What The Guardian (and, earlier, HN) is describing simply isn't a security flaw; rather, HN appears to have had a mild temper tantrum over the lack of a cosmetic "security" feature that, had Chrome implemented it, could have just as easily led to another temper tantrum over how easy it is to bypass.
Post reply on HN