3 ms·
To those saying this isn't insane... you are wrong. I can open anyone's chrome browser and access their passwords without a master password? That's plain fucked
by panacea 13y ago
To those saying this isn't insane... you are wrong. I can open anyone's chrome browser and access their passwords without a master password? That's plain fucked up.
(I realise I could visit sites and use password reset, but this is so frictionless as to be insane)
- victorhooi 13y agoWell, the assumption is, if you cared at all about security, you would actually have a login password, and bother locking your computer? Or you might not just let random people sit down at your laptop and start using it without you being there?
- interpol_p 13y agoThat is not a good assumption. People care about their security and also care about the convenience of being able to let a friend or co-worker use their computer for seconds or minutes at a time without all their passwords being easily discovered. If I debug some code on a friend's machine he would not expect me to be able to open his Keychain and read his passwords. I would need a master password for that. Chrome should do what Safari does — ask for a master password before unmasking other passwords. It would prevent a scenario where one can look up another's passwords inconspicuously and without trace in seconds.
- victorhooi 13y agoErr, I think that's a bit of a strawman fallacy. If you leave your computer unlocked in a public area, that's asking for trouble - which is the example I was referring to. However, in your example, you cited giving your machine to a friend to debug code - in that case, you either trust your friend, or you don't. If you don't trust your friend, why are you giving them your machine then. It's like asking your friend to collect your letterbox mail - do you trust them enough to not open and read your mail? If you don't, then why are you entrusting them to collect your mail?
- interpol_p 13y agoHave you ever glanced slightly harder than you should when your friend enters their four digit pin code on their phone? I have. And it's not out of malicious intent. There are levels of trust. It's not binary, and it's not as simple as you make it out to be. Because Chrome presents your passwords in an easily accessible list from the settings screen, it lowers the barrier to access and increases the opportunity for passwords to be read. Maybe my friend wants to read my passwords out of idle curiosity and they won't do anything malicious with them. I don't know, and I don't want to find out. It is not at all like asking your friend to collect your mail. First, you can easily see if your mail has been opened. And for your friend to "cover up" opening your mail they would have to have some serious intent to breach your trust. This is not so with the password screen in Chrome. I'm surprised that you can't see how making the passwords to all your websites easily accessible and readable in a convenient list is a bad thing. Adding a simple hurdle to access is all that's needed to prevent the majority of casual peeking at peoples' passwords. Safari does this, there is no technical reason Chrome can't.
- obituary_latte 13y agoYou can't open my chrome browser without unlocking my machine. You can't unlock my machine without 2fa. I don't walk away from my machine without locking it. So, technically, there is a master password if you lock your machine. Nb:not saying it is cool to be doing what they're doing.
- RKearney 13y agoThe data on your disk isn't encrypted with two factor authentication though. If someone were to remove your disk drive and crack your password, that second factor doesn't really slow them down.
- obituary_latte 13y agoActually, OSX offers FileVault which is on. The 2fa is a password and yubikey with static pass, so the whole pass is ~40 chars. FileVault uses AES-128 which should, combined with 40 char pass, at the least, slow them down (depending on who it is of course ;)
- masklinn 13y agoIt's especially insane on OSX which already has an OS-wide and ~secure (more secure than this anyway) password manager: Keychain.
- Schlaefer 13y agoNote that Chrome is using keychain and that you can dump the complete keychain data with all passwords decrypted via terminal anyway. You don't need any third party software ala Chrome installed. E.g.: security find-internet-password -g -s news.ycombinator.com Klick allow and that's it. The master password question for showing individual passwords in the Keychain.app does not protect your passwords. As others said: don't let anybody use your computer if you're logged in (have the keychain(s) unlocked).
- panacea 13y ago>The master password question for showing individual passwords in the Keychain.app does not protect your passwords. That's insane too then! as it suggests/teaches that keychain passwords are master password protected.
- Schlaefer 13y agoYes and no. If you're in the Keychain.app a user expects security question for revealing passwords. On the other hand: if you in a third party app you just click "allow" and the app can use that password. Let's read that again: an arbitrary third party app … has access … to a password … by just clicking a button. You have probably done this many times (if you're using a Mac), but without thinking much about it (convenience). Obviously there must be a way so that everyone can write a little app, request and access a password with a single mouse click and then show it in plain text. (Always under the assumption that the keychain is already unlocked.)
- masklinn 13y ago> On the other hand: if you in a third party app you just click "allow" and the app can use that password. Let's read that again: an arbitrary third party app … has access … to a password … by just clicking a button. It's possible to require the master password for each password release, though that is not the default and — in 10.6 — it seems there is no way to enable this globally, it has to be set individually per password as far as I can see.