password safety concern

20 views
Skip to first unread message

Grimm

unread,
Mar 11, 2010, 2:40:50 PM3/11/10
to Chromium-discuss
Hi ,

I started using google chrome about a week ago because firefox is
getting so slow , and i am very happy about google chrome in every
way , but there is one thing holding me off to use it as main
browser .
If you let google chrome save your passwords , it is sooo easy for
someone else to find out your passwords .It takes me 6 clicks to get
to options , personal items , show passwords .
So if you use 2-3 passwords for everything (as most ppl i think ?) ,
it's very easy for someone else to copy them if they get acces to your
computer .
Isn't there a way to fix this ? I was thinking about putting a 'email
me the password' button instead , so they need your inbox password
before they get the rest ...
I don't know if it's just me , and it's not that i don't trust my
friends , but you have to be carefull with these things imo..

JW

unread,
Mar 11, 2010, 2:45:33 PM3/11/10
to Chromium-discuss
I agree, this is completely ridiculous. In OS X, the user should need
the administrator password, to see this. Is there a bug reported for
this yet?

Ben

unread,
Mar 11, 2010, 3:40:53 PM3/11/10
to chromium...@chromium.org
Star this issue for updates (I think):

http://crbug.com/11745

Ben

unread,
Mar 11, 2010, 3:47:48 PM3/11/10
to chromium...@chromium.org
Ah, sorry, I think I read wrong.

The issue is passwords are too easy to access?

That would probably be one of these two:

http://crbug.com/1397
http://crbug.com/812


On 03/11/2010 01:45 PM, JW wrote:

S D Allen

unread,
Mar 11, 2010, 7:16:59 PM3/11/10
to benj...@gmail.com, chromium...@chromium.org
One can turn off that feature and use an extension like LastPass which encrypts the pwd archive on their servers, supposedly. A work-a-round I guess and probably not ideal.

--
Chromium Discussion mailing list: chromium...@chromium.org
View archives, change email options, or unsubscribe:
http://groups.google.com/a/chromium.org/group/chromium-discuss



--
Cheers,
Steve
My Google Profile; http://bit.ly/ddD1gv
http://www.linkedin.com/in/torontostephenallen
http://picasaweb.google.ca/Stephen.D.Allen
http://www.facebook.com/S.D.Allen
http://portfolio-s-d-allen.blogspot.com/
http://friendfeed.com/chimpanze
http://stephenallen.yelp.ca/


Alexander Skwar

unread,
Mar 12, 2010, 2:16:45 AM3/12/10
to jame...@gmail.com, Chromium-discuss
Pardon?

No, the user should NOT need admin rights to see his own passwords
stored in Chrome. He put 'em there without admin pw, so why require
admin pw for displaying the pw?



2010/3/11 JW <jame...@gmail.com>
--
Chromium Discussion mailing list: chromium...@chromium.org
View archives, change email options, or unsubscribe:
   http://groups.google.com/a/chromium.org/group/chromium-discuss



--
Alexander
--
↯    Lifestream (Twitter, Blog, …) ↣ http://alexs77.soup.io/     ↯
↯ Chat (Jabber/Google Talk) ↣ a.s...@gmail.com , AIM: alexws77  ↯

Alexander Skwar

unread,
Mar 12, 2010, 2:20:23 AM3/12/10
to grim...@gmail.com, Chromium-discuss
Hi.

If you only use 2-3 passwords, then this is already basically
insecure. If you change to using 1 password per site, then
you're already protected against attacks against the site which
reveal your password at their server. The most important fix
thus would be to use more passwords - with the help of tools/sites
like LastPass (for which there's a Chrome, Firefox, IE, Safari
extension), this is real easy. Plus you also don't have any
passwords stored on your computer which might be too easy
to get to. The con is, that you need to trust LastPass.com of
course.

BTW: In Firefox, it's just as easy to get to the passwords (if
you don't use a masterpassword).

2010/3/11 Grimm <grimm.vg@gmail.com>
--
Chromium Discussion mailing list: chromium...@chromium.org
View archives, change email options, or unsubscribe:
   http://groups.google.com/a/chromium.org/group/chromium-discuss

Simon

unread,
Mar 12, 2010, 3:02:45 AM3/12/10
to Chromium-discuss
if you don't want your passwords accesable on your harddisk, klick the
"do not save password" button

On Mar 12, 8:20 am, Alexander Skwar <a.sk...@gmail.com> wrote:
> Hi.
>
> If you only use 2-3 passwords, then this is already basically
> insecure. If you change to using 1 password per site, then
> you're already protected against attacks against the site which
> reveal your password at their server. The most important fix
> thus would be to use more passwords - with the help of tools/sites
> like LastPass (for which there's a Chrome, Firefox, IE, Safari
> extension), this is real easy. Plus you also don't have any
> passwords stored on your computer which might be too easy
> to get to. The con is, that you need to trust LastPass.com of
> course.
>
> BTW: In Firefox, it's just as easy to get to the passwords (if
> you don't use a masterpassword).
>

> 2010/3/11 Grimm <grimm...@gmail.com>


>
>
>
>
>
> > Hi ,
>
> > I started using google chrome about a week ago because firefox is
> > getting so slow , and i am very happy about google chrome in every
> > way , but there is one thing holding me off to use it as main
> > browser .
> > If you let google chrome save your passwords , it is sooo easy for
> > someone else to find out your passwords .It takes me 6 clicks to get
> > to options , personal items , show passwords .
> > So if you use 2-3 passwords for everything (as most ppl i think ?) ,
> > it's very easy for someone else to copy them if they get acces to your
> > computer  .
> > Isn't there a way to fix this ? I was thinking about putting a 'email
> > me the password' button instead , so they need your inbox password
> > before they get the rest ...
> > I don't know if it's just me , and it's not that i don't trust my
> > friends , but you have to be carefull with these things imo..
>
> > --

> > Chromium Discussion mailing list: chromium-disc...@chromium.org


> > View archives, change email options, or unsubscribe:
> >    http://groups.google.com/a/chromium.org/group/chromium-discuss
>
> --
> Alexander
> --
> ↯    Lifestream (Twitter, Blog, …) ↣http://alexs77.soup.io/    ↯

> ↯ Chat (Jabber/Google Talk) ↣ a.sk...@gmail.com , AIM: alexws77  ↯

Alexander Skwar

unread,
Mar 12, 2010, 3:04:28 AM3/12/10
to peeter...@gmail.com, Chromium-discuss
Exactly.

And if you fear that somebody gets access to your passwords
while you're not at your system, then simply lock the system
when you leave.

2010/3/12 Simon <peeter...@gmail.com>
Chromium Discussion mailing list: chromium...@chromium.org

View archives, change email options, or unsubscribe:
   http://groups.google.com/a/chromium.org/group/chromium-discuss



--
Alexander
--
↯    Lifestream (Twitter, Blog, …) ↣ http://alexs77.soup.io/     ↯
↯ Chat (Jabber/Google Talk) ↣ a.s...@gmail.com , AIM: alexws77  ↯

JW

unread,
Mar 12, 2010, 9:22:14 PM3/12/10
to Chromium-discuss
Well some kind of master password!

On Mar 11, 11:16 pm, Alexander Skwar <a.sk...@gmail.com> wrote:
> Pardon?
>
> No, the user should NOT need admin rights to see his own passwords
> stored in Chrome. He put 'em there without admin pw, so why require
> admin pw for displaying the pw?
>

> 2010/3/11 JW <jamesw...@gmail.com>


>
>
>
> > I agree, this is completely ridiculous.  In OS X, the user should need
> > the administrator password, to see this.  Is there a bug reported for
> > this yet?
>
> > On Mar 11, 11:40 am, Grimm <grimm...@gmail.com> wrote:
> > > Hi ,
>
> > > I started using google chrome about a week ago because firefox is
> > > getting so slow , and i am very happy about google chrome in every
> > > way , but there is one thing holding me off to use it as main
> > > browser .
> > > If you let google chrome save your passwords , it is sooo easy for
> > > someone else to find out your passwords .It takes me 6 clicks to get
> > > to options , personal items , show passwords .
> > > So if you use 2-3 passwords for everything (as most ppl i think ?) ,
> > > it's very easy for someone else to copy them if they get acces to your
> > > computer  .
> > > Isn't there a way to fix this ? I was thinking about putting a 'email
> > > me the password' button instead , so they need your inbox password
> > > before they get the rest ...
> > > I don't know if it's just me , and it's not that i don't trust my
> > > friends , but you have to be carefull with these things imo..
>
> > --

> > Chromium Discussion mailing list: chromium-disc...@chromium.org


> > View archives, change email options, or unsubscribe:
> >    http://groups.google.com/a/chromium.org/group/chromium-discuss
>
> --
> Alexander
> --
> ↯    Lifestream (Twitter, Blog, …) ↣http://alexs77.soup.io/    ↯

> ↯ Chat (Jabber/Google Talk) ↣ a.sk...@gmail.com , AIM: alexws77  ↯

Alexander Skwar

unread,
Mar 13, 2010, 1:10:54 AM3/13/10
to jame...@gmail.com, Chromium-discuss
A MASTER password would be good, yes. It would be good, because then
the "sensitive" data could be encrypted, which would make it fruitless
for an attacker to read the file containing the passwords and transmit
it "home".

Alexander

> Chromium Discussion mailing list: chromium...@chromium.org

Gootch

unread,
May 23, 2013, 3:07:57 PM5/23/13
to chromium...@chromium.org, jame...@gmail.com, alex...@skwar.name
Reply all
Reply to author
Forward
0 new messages