New issue
Advanced search Search tips

Issue 625887 link

Starred by 3 users

Issue metadata

Status: Archived
Owner: ----
Closed: Oct 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

REGRESSION: can't save different password for multi subdomain!

Reported by bau...@gmail.com, Jul 5 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.60 Safari/537.36

Steps to reproduce the problem:
1. go to adsl.free.fr  use login/password for internet in this provider
2. go to mobile.free.fr use another login/password for GSM in the same provider

What is the expected behavior?
not request to update password! it's not same.

What went wrong?
can't save different password for 2 services in the same domain.

same with drive.intermarche.com / www.intermarche.com / www.les-communautes-actives.intermarche.com

and more more website that use 2 login/password. Example: One is just to connect to forum; other request more secure for access online store.  
www.domaine.com / forum.domain.com

Did this work before? Yes short time

Chrome version: 52.0.2743.60  Channel: beta
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: disabled

with this bad regression; for each password must use Keepass with autotype!
account locked after several failure on many website!
 

Comment 1 by yon...@gmail.com, Oct 14 2016

I can confirm this issue on Linux as well with version 53.0.2785.116

This is also a minor security issue if an attacker has control of a subdomain.

lets say site pix.com allows users to create their own website and host them under USER.pix.com users can login to their account from secure.pix.com 
but if they save the password chrome will auto fill also on attacker.pix.com

(chrome will show the subdomain on the dropdown but even if you don't select it from the drop down it will autofill your password )

So unless the user explicitly select the autofill option from the dropdown it should not autofill the password and subdomains should not overwrite other subdomain passwords
Project Member

Comment 2 by sheriffbot@chromium.org, Oct 16 2017

Status: Archived (was: Unconfirmed)
Issue has not been modified or commented on in the last 365 days, please re-open or file a new bug if this is still an issue.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment