Skip to content

Comment on Google Chrome security flaw offers unrestricted password access

Comments

Given that:

- I understand the fact that the browser must be able to have the password in plaintext at the moment of logging to a website.

- I understand that if someone has access to my account on my computer then is able to access all the sensitive information that I have stored unencrypted on it, and not just my browser's passwords.

- I understand that is not something new or ground-breaking, or even something exclusively related to Chrome.

I still can't see how sensible having an option to show the passwords in plaintext, without protection, really is. Many people (non tech-savvy people in particular) for example do not lock their OS profile at all.

Requiring a Master Password by default (with the possibility of opting out in the settings) before using/showing passwords, and storing these in crypted form it would seem more sensible to me.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.