[Chrome - Personal Stuff - Password Showing] Dangerous and insecure feature

48 views
Skip to first unread message

HYEON

unread,
Apr 12, 2011, 5:08:14 AM4/12/11
to Chromium-discuss
Dear Developers and Users,

First of all, I really appreciate the Chrome browser. It is great
master piece, working lightening fast and having really nice and fancy
interface.

I would like to open discussion about "Manage Saved Passwords" in
personal stuff option.
It is good to manage the list of saved passwords, and provide users a
function to delete selectively,

BUT the problem is SHOWing the password. I think that is unnecessary
function for users.
If users do not remember their passwords, they can find it from
service providers.
It is all right to save passwords in Chrome browser, HOWEVER, showing
them to any user is different matter.

It means any one using Chrome can be hacked by just opening the
password management function.
I believe that just SAVING and DELETING are enough, BUT further
feature SHOWING PASSWORDS is a MUST-NOT-BE INCLUDED-FUNCTION. I also
hope that the passwords would be encrypted by some secure encoding
feature.

Some people can say that Chrome would be used just personal purpose.
BUT I believe that Chrome can be a public web browser even in Internet
Cafes.
So, this insecure feature should be removed.

Thanks for reading

Best regards,
Hyeon

Joao da Silva

unread,
Apr 12, 2011, 5:39:19 AM4/12/11
to tinyst...@gmail.com, Chromium-discuss
Hi Hyeon,

you might be interested in a policy that does just that:

http://www.chromium.org/administrators/policy-list-3#PasswordManagerAllowShowPasswords

Please also take into account that an "attacker" could also just
navigate to some interesting site (gmail.com, for example) and take
the password that is automatically filled in. This can be prevented
with another policy:

http://www.chromium.org/administrators/policy-list-3#AutoFillEnabled

Policies are meant to administer chrome instances in enterprises and
other settings like, as you mentioned, Internet Cafes.

Hope this helps!
Joao

> --
> Chromium Discussion mailing list: chromium...@chromium.org
> View archives, change email options, or unsubscribe:
>    http://groups.google.com/a/chromium.org/group/chromium-discuss
>

Nate

unread,
Apr 13, 2011, 3:48:59 PM4/13/11
to Chromium-discuss
I'd have to agree with the original post here. With simply a saved
password one can access their account from only one computer (or any
that are synced to that same account), but by showing it in the menu
Chrome allows the password to be stolen and used from any device with
internet access, in addition to giving the "attacker" the ability to
change that password or even distribute it to others–– in which case
the user is really screwed.

On Apr 12, 5:39 am, Joao da Silva <joaodasi...@chromium.org> wrote:
>  Hi Hyeon,
>
>  you might be interested in a policy that does just that:
>
> http://www.chromium.org/administrators/policy-list-3#PasswordManagerA...
> > Chromium Discussion mailing list: chromium-disc...@chromium.org

Caleb Eggensperger

unread,
Apr 13, 2011, 4:46:41 PM4/13/11
to bign...@gmail.com, Chromium-discuss
Hiding the passwords in the menu just gives you a false sense of security; as Joao said, they can be taken directly from the page anyway.

If you don't like this, don't use password saving.

Chromium Discussion mailing list: chromium...@chromium.org

View archives, change email options, or unsubscribe:
   http://groups.google.com/a/chromium.org/group/chromium-discuss



--
Caleb Eggensperger
www.calebegg.com

Gootch

unread,
May 23, 2013, 3:10:08 PM5/23/13
to chromium...@chromium.org, bign...@gmail.com
We need something like this: http://www.youtube.com/watch?v=6mkcUdytggU
Reply all
Reply to author
Forward
0 new messages