3 ms·
i have to admit, I have tired of this type of amateur hour, alarmist analysis. > Well, no. If a hacker has managed to get access to your computer, whether it b
by techslave 8y ago
i have to admit, I have tired of this type of amateur hour, alarmist analysis.
> Well, no. If a hacker has managed to get access to your computer, whether it be through an unprotected port or a botnet-type trojan that you’ve managed to get infected with, then the hacker already has your Windows credentials ...
If the hacker has your Windows credentials and local access, nothing Chrome does matters. It’s game over for you. (local 2fa aside, ie touch ID mediated keychain access, that kind of thing.)
Had the author reported it to google before declaring his brilliance over GOOGLE’s obviously deliberate choice here, he might have gotten some valuable insight and not embarrassed himself with this post.
- OskarS 8y agoI don't agree. Lets say someone steals your computer and is able to log in: if you save all your passwords in Chrome this way, you're done. Every password to every site you've ever logged into will be compromised. You've lost all control over your online identity. However, if you had used a password manager with the passwords encrypted with your master password at rest, it would be fine. This doesn't just apply to physical thefts: if you get malware on your computer, fetching all your Chrome passwords is trivial. Fetching your password manager passwords is not: it would only be possible to do if you actively used the computer while it was infected (and entered your master password), and even then it's not trivial. You'd have to either keylog every keystroke and figure out which ones are the master password (if a master password was even used, you can log into 1Password with TouchID and Windows Hello) or try and go digging into the memory of the password manager to try and fish out any passwords. Not an easy task, and one that is very difficult to automate. Compromising a password manager, even when the computer itself is compromised, is difficult. It takes dedication and personal attention from the hacker. Browser passwords, on the other hand, can be trivially harvested the second you compromise a computer. It needs no personal attention, a bot could easily do it on a massive scale. The advice is correct: don't save your passwords using any system that doesn't properly encrypt them. EDIT: to be clear, this is not because Google's engineers are stupid. It's because they want the Chrome password management system to be convenient, and they don't want to require a master password. If that's the case, then there's not much you can do to prevent this sort of thing.