4 ms·
Basically: * Normally you can't access Chrome's decrypted cookie storage unless you're in an interactive session and you've unlocked the keychain. * An attack
by snacktaster 8y ago
Basically:
* Normally you can't access Chrome's decrypted cookie storage unless you're in an interactive session and you've unlocked the keychain.
* An attacker running code on your computer (nefarious NPM package, etc) can spawn a headless chrome session with remote debugging enabled and then slurp out all the decrypted cookies through the remote debugging socket
Chrome is very frightening to me. It's just this massive God program that has a huge attack surface and a lot of really valuable goodies like this that attackers would love to get at.
- munchbunny 8y agoChrome is very frightening to me. It's just this massive God program that has a huge attack surface and a lot of really valuable goodies like this that attackers would love to get at. I think the right way to look at it is that it's a smaller OS. Different in nature, but browsers are now in the OS league for how much damage a compromise can do.
- ferongr 8y agoYou can steal Firefox cookies and even passwords easier, they're stored unencrypted in the user profile directory.
- snacktaster 8y agoyes i know
- PhantomBKB 8y agoYou can set a master password
- jbroman 8y agoMost desktop OSes aren't designed to defend applications run by the same user from one another. As a consequence an attacker running unsandboxed code with your user privileges is an attack that's very difficult to defend against.
- zonidjan 8y agoBut Chrome can't access it until you've unlocked the keychain either, which means this "exploit" doesn't do anything... Also I don't know about you but I've never needed to enter a password to start Chrome, so...