New issue
Advanced search Search tips

Issue 606540 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 3
Type: Bug

Blocking:
issue 777268



Sign in to add a comment

False-positive on detecting password change on vanguard.com

Project Member Reported by arnarb@chromium.org, Apr 25 2016

Issue description

Version: 50.0.2661.86
OS: Mac

What steps will reproduce the problem?
(1) Save password on vanguard.com to Chrome passwords
(2) Log in with no cookies, vanguard.com will prompt a security question
(3) After logging in, chrome offers to update the stored password

What is the expected output?
Password wasn't changed, so didn't expect chrome to ask to update the saved one.

What do you see instead?
Chrome detects the answer to the security question as a new password. If you answer yes to the update question, the security question answer is saved, overwriting the actual password.

Please use labels and text to provide additional information.

 
Cc: vabr@chromium.org
Owner: dvadym@chromium.org
Status: Assigned (was: Untriaged)

Comment 2 by dvadym@chromium.org, Apr 27 2016

Thanks for the report.

It looks like the Password Manager thinks that a security question is retry password form. We are working on adding more intelligence in Password Manager and probably will be able to fix it. 

Could you please also open chrome://password-manager-internals/ in a second tab, then log in in the first one, and then share the logs? (The logs won't contain your username or passwords, just the structure of forms seen and the events observed by Chrome). That would help us to understand more what happens, as this page does not allow registering free accounts for testing.

Comment 3 by arnarb@chromium.org, Apr 29 2016

Somehow the security question isn't triggering the update prompt now, but here is the log.

Version: 52.0.2715.0
pwdmanagerlog.html
19.2 KB View Download
Thanks a lot for the log. I hope we will be able to fix such cases with adding some intelligence in Password Manager.

Comment 5 by kolos@chromium.org, Jan 26 2018

Blocking: 777268
Cc: -vabr@chromium.org
vabr going hobby only -> reducing involvement.
Please contact me directly in urgent matters.

Sign in to add a comment