Issue metadata
Sign in to add a comment
|
Security: login to any account even after closing incognito windows just because to one small fault in chrome
Reported by
ranjeets...@iisertvm.ac.in,
May 29 2016
|
||||||||||||||||||||
Issue descriptionVERSION Google Chrome Version: Version 50.0.2661.102 (64-bit) Operating System: [OS X EI CAPTION 10.11.4 (15E65)] REPRODUCTION CASE As we know that incognito windows do not save anything. Because of that function people use incognito windows when they login other computer(like in cyber cafe or friends computer). But I found one way to login in someone account if they use incognito windows. Steps are following. Step 1 : open a incognito windows and login to wifi [in my case it is Dell sonic wall]. a popup windows will open to show the status of login time. Step 2 : Close the original incognito windows.[not popup window] [problem in chrome is that the popup windows opened is not seems like incognito window] Step 3 : invite someone and ask him to open new incognito window and login in gmail or facebook. [popup window of wifi login is seems like normal window so people do not close that] step 4 : close incognito windows. Step 5 : Click on "SSLVPN Portal" in popup windows or open new incognito then new incognito will open. Step 6: open gmail or facebook. the gmail will open without asking username or password. I think the popup window should have different colour like actual incognito windows so that other people can find out that they have not closed all incognito windows.
,
May 31 2016
Thanks for the report. Incognito mode cleans up only after all incognito windows are closed. You are right that popup windows don't have an incognito indicator, and this bug was reported earlier at bug 76735 . Note that incognito isn't a security feature: It's not intended to share the same computer between users. For that, you should use OS accounts. Please see https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-
,
Oct 2 2016
,
Sep 14
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ranjeets...@iisertvm.ac.in
, May 29 2016