5 ms·
A little brother using Chrome regularly won't know about keyloggers, how to write a clever bookmarklet, or even be allowed to be around when his big sister is t
by Ovid 13y ago
A little brother using Chrome regularly won't know about keyloggers, how to write a clever bookmarklet, or even be allowed to be around when his big sister is typing in her password. But there's a good chance he does know about clicking that little icon, choosing "settings", and seeing all of his big sister's passwords when she's out on a date and forgot to lock her computer.
Locks on your front door knob are not there to keep out burglars. They're there to prevent opportunistic crime: someone who tries that doorknob out of curiosity and discovers a home full of stuff and no one around. There's a large middle ground between good guys, bad guys, and those who might, just might, be tempted to be bad when they find that suitcase full of money. That's what Google is missing here.
And in a condescending response[1], someone who is allegedly the Google head of Chrome security called the original author a "novice", claimed Google has "quite a bit of data" to back up their case (without describing the data, its source, or how it was evaluated), and suggested that a master password would make security worse by providing a false sense of security.
First, I would suggest that if Google really does have the data mentioned in the claim, release it. Second, a master password isn't going to make the computer safer from a determined black hat because physical access to the machine means game over, but THE MASTER PASSWORD IS NOT ABOUT PROTECTION FROM BLACK HATS.
When the colleague who hates you is standing by your unlocked computer when you're off to get coffee and suddenly realizes that he not only can read your email now, but at any time he wants to in the future, that's a problem — when your partner gets suspicious about your working long and you've forgotten to log out — when your little brother realizes he can post "funny" pictures to your Facebook page ... when, when, when ... there are so many areas where this could cause a lot of pain. For example, this is from a blog entry I wrote a decade ago about a young lady who was compromised because LiveJournal stored her username in the cookie and the conservative, religious parents found her blog[2]:
I know of a young lady who kept an online journal. Her
parents found it and started reading it and were
horrified to find out that she was suffering from --
brace yourself -- teen angst! Her parents don't
understand her, not enough boys like her, she's not very
popular, etc., etc. In reading through the journal,
there are no references to doing drugs, sex, or anything
else that one might expect a parent to worry about, but
this young lady's parents hit the roof. They forbid her
to keep an online journal and they grounded her
(naturally, I'm sure this cured the angst problem).
The parents had physical access to the computer and were smart enough to look at cookie data (these parents weren't technically sophisticated, I might add). Can you imagine what would have happened if the parents could then have read all of their daughter's passwords? Google telling users "this isn't really secure, so we're not going to do a damn thing to help you" doesn't help.
Google is optimizing against black hats but pretending that opportunistic crime doesn't exist. In physical security, opportunistic criminals tend not to be the brightest or think too deeply about what they're doing, but when the opportunity is there, they go for. Google is happy to give them that opportunity.
1. https://news.ycombinator.com/item?id=6166953 https://news.ycombinator.com/item?id=6166953
2. http://use.perl.org/use.perl.org/_Ovid/journal/13471.html http://use.perl.org/use.perl.org/_Ovid/journal/13471.html
- thezilch 13y agoYou're confusing a browser password-keeper with a house lock, when the house is actually synonymous to the machine. Lock the machine. Should every OS come with only encrypted filesystems that you have to enter a password on every read? You know, so your brother doesn't find your sexts logs?
- Ovid 13y agoMore and more of our data is being stored online. Many things that you might want to keep confidential is nonetheless behind a poorly designed "firewall" of passwords. That's the problem. Demanding that someone never forget a manual process (locking the machine) is adding a massive point of failure. This is bad.
- thezilch 13y agoWhat does that have to do with a browser and poor analogies? Neither protect important documents on disk, a shell open with root, an ssh open to your production, etc. I'm not condoning Chrome's actions, but I'd also demand not storing passwords in a browser at all, and do all sensitive browsing in incognito, so your sessions can't be lifted.
- baddox 13y agoBut you can always conceive of some would-be attacker with a given skill level. You conceived of a child who knows about Chrome settings but not about keyloggers, and thus concluded that there should be a master password in the browser. But I could just as easily conceive of an attacker who knows how to read a computer screen but doesn't know how to use basic window management, and thus conclude that the browser window should always display all saved passwords as long as the user can minimize the browser. Or toward the other end of the continuum, I could conceive of an attacker who knows how to install a keylogger but doesn't know how to lift and spoof fingerprints, and thus conclude that the browser should require a fingerprint scanner to recall saved passwords. These arguments need to establish why the line should be drawn in that specific spot, rather than just mentioning the line and describing the types of attacks it can thwart.
- 13y ago