I mean, he's absolutely right in that if you have physical access, or if you have OS account access to a computer, it really doesn't matter what you do, your shit isn't safe any more.
The argument of a 'crime of opportunity' doesn't play out in the digital world. Everything in the malware world is so automated and the scenario of 'If there are exposed passwords on this particular machine, I'll take them' just doesn't ever play out.
To that end, while it certainly seems awkward from a 3rd party perspective, I'm kind of agree with Google on this one.
I would like to ask to think twice until agree Google's reply. And not only because they have so much power on the Internet.
Think about most simplest case: childs John and Jack do their homework on Jack's computer. Jack goes to the toilet and John continue the writing/drawing. Then John gets "brilliand" idea: "Hmmm, why not stole his passwords all around and sell/play them later..."
Is this something which you think never happen?
There is two simple solution to avoid this:
1) Jack is having two accounts: admin and JackTheUser
2) There are no passwords in clear text format unless someone add JackTheUser's credentials. And this must happen everytime you look the passwords.
#1 makes impossible to install any bad software
#2 avoid simple friends to see your passwords
Maybe Justin and Google just doesn't know how to verify user on the OS? Very same way than UAC behaved earlier on Windows.
Some professionals call it layer security: if your front door is open, your safety box is still locked. May I ask, is that something which we do not want?
That's not realistic. Do you work with your personal laptop in a work environment? I do. Sometimes you're debugging on a co-worker's machine and they step out of the room to get some water.
This flaw makes it possible to read their web passwords in a manner which is not suspicious, quick, and not easy to trace.
If it even took slightly longer, or there was a risk of being caught attached to this action it would be far less likely for someone to casually browse another's passwords.
Comments
I'm inclined to agree with Justin here.
I mean, he's absolutely right in that if you have physical access, or if you have OS account access to a computer, it really doesn't matter what you do, your shit isn't safe any more.
The argument of a 'crime of opportunity' doesn't play out in the digital world. Everything in the malware world is so automated and the scenario of 'If there are exposed passwords on this particular machine, I'll take them' just doesn't ever play out.
To that end, while it certainly seems awkward from a 3rd party perspective, I'm kind of agree with Google on this one.
I would like to ask to think twice until agree Google's reply. And not only because they have so much power on the Internet.
Think about most simplest case: childs John and Jack do their homework on Jack's computer. Jack goes to the toilet and John continue the writing/drawing. Then John gets "brilliand" idea: "Hmmm, why not stole his passwords all around and sell/play them later..."
Is this something which you think never happen?
There is two simple solution to avoid this: 1) Jack is having two accounts: admin and JackTheUser 2) There are no passwords in clear text format unless someone add JackTheUser's credentials. And this must happen everytime you look the passwords.
#1 makes impossible to install any bad software #2 avoid simple friends to see your passwords
Maybe Justin and Google just doesn't know how to verify user on the OS? Very same way than UAC behaved earlier on Windows.
Some professionals call it layer security: if your front door is open, your safety box is still locked. May I ask, is that something which we do not want?
That's not realistic. Do you work with your personal laptop in a work environment? I do. Sometimes you're debugging on a co-worker's machine and they step out of the room to get some water.
This flaw makes it possible to read their web passwords in a manner which is not suspicious, quick, and not easy to trace.
If it even took slightly longer, or there was a risk of being caught attached to this action it would be far less likely for someone to casually browse another's passwords.