13 ms·
Okay. But is it possible for some malicious addon/website to get this information? Also, what happens if google decides to spy on someone? Basically, is it pos
by aps-sids 13y ago
Okay. But is it possible for some malicious addon/website to get this information?
Also, what happens if google decides to spy on someone? Basically, is it possible that chrome sends some data to google servers even without user signing in for sync?
- itsprofitbaron 13y agoIf that malicious addon/website can compromise your local machine then, yes the information can be accessed. Similarly, when you aren't using https the password is sent in plain text and could also be accessed then as well.
- atesti 13y agoIf something malicious gets onto your computer, it's game over anyway! Any malware (chrome extensions, software running on the computer, even not as administrator) can start to listen to all keyboard events, all virtual keyboards like they are used in Korea mandated by government for security, all network traffic (even encrypted by hooking the APIs, etc. So once the malware is on your computer, it can get all passwords entered afterwards. The only harm in saving passwords in Chrome is that the malware can get all passwords at once and does not have to wait for you to login to all important pages eventually. If the computer is stolen and not given back compromised, then it is safe, because Chrome encrypts the passwords using the Windows password API which encrypts it using the user password