Skip to content

Comment on Chrome's insane password security strategyparent

Comments

From my office workstation, in this list I can read password of my personal NAS that I only access from home.

Does it means that all these passwords are stored in my Google Account ?

Does it means that applying steps below is possible ?

1. Steal Google credentials : By using phishing or simply access the password Chrome page of an unmonitored screen (it only requires 10 seconds), 2. On a other system, use the stolen Google credentials to connect on an blank Chrome installation, 3. Open the password list page, and get access to all the passwords registered in the Google Account.

If it works, it provides a long term remote access to all the passwords stored on the targeted Google Account.

Even if the targeted user changes the stored passwords (Facebook, ...), as long as it stores them on Chrome and does not change its Google password, I can get all the password changes.

Please, tell me that I missed something, and that I am wrong ...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.