New issue
Advanced search Search tips

Issue 622383 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Security



Sign in to add a comment

Anyone can access user's saved passwords

Reported by abhishek...@gmail.com, Jun 22 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/48.0.2564.82 Chrome/48.0.2564.82 Safari/537.36

Steps to reproduce the problem:
1. Open chrome browser.
2. Go to advanced settings in Preferences of browser.
3. Go to manage password under advanced settings.
4. Click on any account of user listed under saved accounts.
5.Click on password show option and hence the password is visible.

What is the expected behavior?
The expected behavior is to save user's password in encrypted form as like in Windows and Mac OS.

What went wrong?
The password is visible to everyone and its threat to user's privacy.

Did this work before? No 

Chrome version: 48.0.2564.82  Channel: n/a
OS Version: 15.10
Flash Version:
 
Screenshot from 2016-06-22 22-56-42.png
139 KB View Download
Status: WontFix (was: Unconfirmed)
This is working as intended - if a malicious entity has physical access to your machine, then we basically can't do anything. [1]

On Windows and Mac, you are prompted for your computer password before you can view Chrome's saved passwords. This mitigation isn't yet available for Linux and ChromeOS - the feature is filed as issue 615690.

[1] https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-
Project Member

Comment 2 by sheriffbot@chromium.org, Sep 29 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment