4 ms·
I once leaned heavily upon Google Chrome as my password manager, but then I discovered that you could view the passwords in Chrome for Windows by knowing my Win
by crumpled 4y ago
I once leaned heavily upon Google Chrome as my password manager, but then I discovered that you could view the passwords in Chrome for Windows by knowing my Windows login password, instead of my Google password.
This feels off topic a little, but in all the discussion of password managers lately, I seldom hear people talk about the web browser being a good/bad idea. It almost feels like they are slipping through the cracks of the conversation.
For the record, I no longer use that platform for important passwords or secrets, ("driver carries no cash")
- amelius 4y agoI personally use Firefox Sync (it's built in the browser) and am very happy with it.
- Someone1234 4y agoThe article talks about a security weakness with Firefox Sync in the same vain.
- amelius 4y agoGood point.
- mk_stjames 4y agoI noticed this as well, I used to do the same and so did everyone I know. I stopped used any Chrome based solution after seeing that if my Chrome was sync'd to my phone, and my phone was unlocked, someone could open Chrome on my phone and, with only my phone's PIN to unlock the vault, view all my passwords. This seemed super weak. So I switched to a different method of storing and generating passwords. But as far as I know, most people I know just use Chrome's password manager. And you know... I haven't ever heard of a Google breach where vault databases have been breached...
- kibwen 4y agoNote that if you have autofill enabled on website login pages, then password-protecting the browser's password store doesn't do anything. Anyone with your Windows password can just go to any website, autofill the password, and then copy the password out of the page itself. Try it on HN, go to the login page and run `document.getElementsByName("pw")[0].value`. To say nothing of the fact that, if they used some method to divine your Windows password, then they've probably already done the same for your password manager's password. And even if they only had your Windows password somehow, they could just install a keylogger to get your master password anyway. And even if you 2FA your password manager, the keylogger can still intercept any other password and take over any non-2FA'd accounts.
- tjbiddle 4y agoI've bought a few online businesses; and when doing so - we of course transfer various online accounts. Once, I was given the primary Google account and as I was going through and updating security items on that account I discovered the previous owner had been using Google's password feature and I could login to a whole slew of his personal accounts (Not just the "Login with Google" ones). Of course, I just deleted all those - but the risk of centralization was certainly highlighted in that moment.