3 ms·
This should be reported to the Google Team and perhaps they should award the author some compensation as part of their bug bounty program. This is alarming.
by AngeloAnolin 8y ago
This should be reported to the Google Team and perhaps they should award the author some compensation as part of their bug bounty program.
This is alarming.
- pard68 8y agoI thought this was known. In fact KeePass has a plug in which will automatically grab all chrome passwords and import them into KeePass. I used it about two years ago to do this.
- hrktb 8y agoit’s pretty old, for instance this is a description of the same issue from 2013: https://www.howtogeek.com/70146/how-secure-are-your-saved-chrome-browser-passwords/ https://www.howtogeek.com/70146/how-secure-are-your-saved-ch... The link to the “why isn’t there a master password?” question is now dead, but from memory of the disucssion at that time, it was basically said that browser passwords are inherently unsecure as they end up in plain text in the password field, and trying to add layers upon layers of encryption was just distracting from that fact. That position explains a lot about how Chrome handles these passwords.
- techslave 8y agothere’s a difference between reading one password out of a password field being actively used, and your entire archive from cold storage. that said, as i commented otherwise, the report is still bogus.
- tylerl 8y agoThis is not a bug. Nor is it news. It's an intentional design decision from years ago. The alternative is requiring users to manually enter a "vault" passphrase every time they start chrome, to unlock both the password vault and the cookie store (remember, your cookies are effectively passwords too). This has been tried, and the overwhelming consensus from users is "DO NOT WANT". So encrypting to the data at rest, and unlocking it with user login is generally accepted as a reasonable compromise.