Skip to content

Comment on Chrome's insane password security strategyparent

Comments

You're right, locking the operating system will secure it. But people aren't doing that. And people lend their computers to friends sometimes. It happens. I think the actual situation is that you don't understand how people are using computers, and how people expect them to behave - which is very important.

Your software allows me to open up one application and see all passwords. It's likely the single most-used application, and the easiest attack vector on the machine. If I wanted your password, I'd try Chrome first. It's very widely-used, and therefore a huge vector. That is the problem here.

Either change it, or better communicate the need to lock your system. Because to an average user on the street, this is a scary thing to be able to do so easily.

Is there a public point of contact that I can speak to about this?

Elliottkmember is right here. Chrome's approach to this is absurd. What if you simply don't want friends, coworkers, significant others browsing your passwords? At least tell users that if they choose to save passwords in Chrome, that everyone who uses their computer, even pretty non-technical people, will be able to access those passwords. Tell them that storing their passwords in Chrome is unsafe.

Justin, can you tell us the real reason Chrome does it this way? Because the reasons you list so far don't make sense.

Please don't invent motivations for the statements people make when you don't like what they've stated so far.

If you don't want people browsing your passwords, you can't ever give them access to your user account or your unlocked desktop. That's it, that is the entire solution. Any other method of protecting the passwords is vulnerable as long as the potential attacker has physical access to the unlocked desktop.

Now, perhaps some of this is mitigated by the fact that most of those friends, coworkers, significant others won't know how to install a keylogger or install extensions - but some small percentage will anyway, and those users who were lulled into a false sense of security will have been just as exploited anyway.

If you don't want people browsing your passwords, you can't ever give them access to your user account or your unlocked desktop. That's it, that is the entire solution.

Nope.

Just don't use Chrome. That's an even better solution.

Hahahahahhhh.

Let me teach you a neat trick (I'll use firefox as an example, but this can be done in any browser because it's a "feature" of HTML).

Open firefox and navigate to a login page where your password is saved
Right click on password box and click inspect element
In the console, change type="password" to type=""
Move your eyes back to the password field

Oh dear, what's this?!

Protip: Don't store your passwords in your browsers if you let other people use your computer. End of story.

Ha... The people complaining really are novices, looking for something to get outraged over. Every operating system allows multiple user accounts. I recommend people start learning how to use them.

I'm not a novice, but I would prefer that it wasn't trivial for a novice to access my passwords if I'm away from the keyboard for 30 seconds. A novice is going to have not a single clue of what to do with a console, but they can get at passwords in plaintext with four clicks with Chrome. No other browser makes it this easy to get at passwords in plaintext.

No other browser makes it this easy to get at passwords in plaintext.

In Firefox you can go to preferences, security, and saved passwords. And News Flash: If you leave your wallet unattended for 30 seconds, someone could take your money. I guess wallet makers should include a warning too?

In Firefox you can go to preferences, security, and saved passwords.

Incorrect if you set a master password, which Firefox allows you to do and is the reason why everyone's saying 'wtf, chrome?' and leaving firefox alone.

IF you set a master password... But how many people do that? By the way, you can set up user profiles in Chrome.

That's not the point. The point is that Chrome lacks this option, which, again, is why nobody's heckling Firefox right now. This isn't a thread about people failing to configure their software, it's a thread about a popular piece of software that's bungling some trivial security features.

How many? ALL the smart people.

As for the dumb ones, they're storing their passwords on a sticky-post. Or using Chrome.

Thanks. By chance, I needed to recover a password (one of my own of course) today and I remembered that trick.

Right, I'm not arguing against any of that. The point is if it's going to be that insecure, Chrome should make more of an effort to make it clear. They could do this by displaying a warning alongside the prompt to save a password.

Also, just because some people will be able to access the passwords with physical access doesn't mean it's not worth doing basic/unsecure locking. I'd rather use a system where people need to have the know how to use keyloggers in order to break, over one where Joe Schmoe can walk in and take everything.

In the end I have always known the security issues with saving passwords so I don't save any banking passwords or email account passwords in any browser.

"The point is if it's going to be that insecure, Chrome should make more of an effort to make it clear"

And what's a better way to make it clear than actually showing the passwords ?

A better way (than showing the passwords) to make it clear that storing the passwords is insecure was in the very next sentence after the snippet you quoted.

Read this: https://en.wikipedia.org/wiki/Principle_of_least_astonishmen...

Then tell me what's better:

- Asking users to store password, and having a menu hidden in the guts of Chrome's settings that most users will never look at.

OR

- Asking users to store password, and prompting them at the same time that doing so is insecure.

Keeping in mind that the vast majority of users of this software are average, non-techies.

What about the situation where I drop my computer off for service. While I may remember to delete all the passwords, I doubt my dad will...Now we have the possibility that a service tech who I will never meet can harvest credentials and sell them on the black market.

The real reason is simple. Get people to fear their real life circles so that, by contrast, they'll be more inclined to share their private information on the Internet.

After all, google's business model depends directly on how much private information is shared over much of the internet.

1) Chrome doesn't show "all passwords". It only shows passwords that Chrome knows about. The two categories might overlap, but they're not actually the same.

2) Either the browser demands an unlock password every single time it queries the password store--which is probably not an acceptable experience for most users--or the browser can arbitrarily read the password store when left unattended. There's no meaningful middle ground here. An option to demand a credential before unlocking the store might be nice for nerds, but nerds don't need it anyway, because they can use 1Password (or similar) to do this for them. It's simply not tenable for normals. Good grief, just look at the wailing and moaning that the UAC prompts in Windows Vista generated. Those prompts by default didn't even demand credentials, just a click through.

Hm, I agree with the author of the article on this. I think, the default should be, that the user will be prompted to define a master password, which unlocks the password store. User might choose not wanting to set this password, but then he should be warned that all his stored passwords will be accessible by anyone using his computer with his credentials.

"his stored passwords will be accessible by anyone using his computer with his credentials."

But this is EXACTLY Justin's point: EVEN with a master password, they'd be accessible in other ways by anyone using his computer, because it's just stored in the keychain - and if they add a master password, people will think that makes it more secure.

The solution here is to remove the show button - don't add any kind of master password - because that's just snake oil.

EVEN with a master password, they'd be accessible in other ways by anyone using his computer

Maybe (there are simple but very effective prevention methods against keyloggers etc.), but the main point is: it's not all black and white. There are varying levels of security (and varying levels of "hacker skills"). Passwords encrypted with a master password are at least a couple of levels safer than those displayed in plain text.

If they're autofilled, which is the very reason to store them, then it doesn't matter how deep you store them. The browser will dig it for you automatically.

But only after the password store was decrypted after providing the master password, or not? And that is good enough for me. If I let someone to use my computer, of course I will close the browser before. So he can use my computer, launch the browser, but will not be able to access my passwords, since he doesn't know the master password.

If you actually _want_ someone's password and you have access to their account, there are many things you can do, all equally easy.

The more interesting argument here is the "crime of convenience" - where someone didn't want the passwords, but just saw them laying around in plain sight. But that isn't actually the case in Chrome: it's like four clicks. You have to actually be trying to find them.

The point is that 4 clicks is a LOT more convenient than most people would expect.

Not to mention this doesn't seem to be an oversight by the Chrome team - it seems this is 'as designed'.

Isn't a more likely crime of convenience that you hand your friend your computer, he types "gmail.com" to login to his mail, but he automatically logs in to your gmail, and then he realizes he can do pretty much anything on your computer as you now (including changing all passwords linked to your gmail account)?

Why are you more concerned about something he has to go digging through settings purposely to find, than something he is almost guaranteed to stumble across?

Wrong. Who cares if chrome shows the password? If someone has access to the browser with saved passwords they can easily just go to a site that's been saved and login and change said password so having chrome not show the PW would do ABSOLUTELY NOTHING

The use case people are talking about such as a jealous partner/spouse, or coworker, or only has access to a computer for about 30 seconds while your in the bathroom, does not have enough time to search through all of your gmail or accounts, nor would they want to change your password since then clearly you would know. What they would want to do is see your password, and then later on when there alone they could login to your account on their own computer and casually browse your accounts without your knowledge. Yes Gmail in tiny letters in the footer says if your logged in at two locations but once again this is in regards to non technical users like your parents.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.