3 ms·
The data being synced is completely encrypted end-to-end, and you can provide a personal passphrase aside from your Google credentials as an added level of secu
by sid0 15y ago
The data being synced is completely encrypted end-to-end, and you can provide a personal passphrase aside from your Google credentials as an added level of security if you'd like.
I'm having trouble parsing this comment -- part of any "end-to-end" encryption would be an additional passphrase not known or accessible to Google in any form. Obviously Google knows about your Google credentials, so merely the credentials are not sufficient to get "end-to-end" encryption.
Also last I checked the personal passphrase only encrypted passwords. I haven't used Chrome in a long while, so has that been extended to all your data yet?
- Pewpewarrows 15y agoIf you think Google has access to your raw, plaintext credentials logged somewhere on their servers, I have a Nigerian banker to forward your way who'd love to give you a million dollars if you help him up-front with a little cash.
- scrod 15y agoNope, you're wrong. Google will always be in a situation where they can read your password. Otherwise authentication to the rest of their services would be impossible.
- Pewpewarrows 15y agoAgain, it's sad if you think they're actually logging everyone's plaintext credentials. Which is besides the point, because in the latest versions the additional non-Google account passphrase extends to all the encrypted data it syncs.
- nknight 15y agoI seriously doubt Google is dumb enough to store user passwords in plaintext. There is absolutely no reason to. Passwords get stored as non-reversible hashes.
- scrod 15y ago>I seriously doubt Google is dumb enough to store user passwords in plaintext... And who said they'd need to store anything? The only need access to them once in order to defeat any kind of local encryption scheme based on your Google account password.
- sid0 15y agoIf you think Google has access to your raw, plaintext credentials logged somewhere on their servers I don't think that. Read my comment again, paying special attention to the phrase "in any form".
- Pewpewarrows 15y agoExactly. For it to be any less secure, they'd have to be logging your plaintext credentials. And if you're that paranoid, there's the additional passphrase.