Skip to content

Comment on Chrome's insane password security strategyparent

Comments

So Chrome should not allow passwords to be read without the system Keychain password.

There is no technical reason it can't do this. Safari does this if you want to view passwords.

Chrome makes passwords casually available, this is unlike Safari and unlike the Keychain. So either Chrome informs the user of that behaviour or it stops doing it.

What it is doing now is very poorly designed behaviour. I am surprised that you are arguing for Chrome's current implementation.

I fail to see how it is beneficial to the user. As you say, most non-technical users don't know about chrome://settings/passwords, these are also the group of users who most likely need to be reminded of their passwords. So what Chrome is doing is essentially allowing slightly technically competent users to easily peek at the passwords of the "vast majority of the population." Bad design that is easily fixed.

There is no technical reason it can't do this.

Not all OSes have a "Keychain".

So do it on the ones that have this feature. Try to find equivalents on others.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.