New issue
Advanced search Search tips

Issue 649788 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: ----



Sign in to add a comment

Viewing saved passwords

Reported by vanajvid...@gmail.com, Sep 23 2016

Issue description

This template is ONLY for reporting privacy issues. Please use a different
template for other types of bug reports.

Please see http://www.chromium.org/Home/chromium-privacy for further
information.


PRIVACY ISSUE
Please provide a brief summary of the privacy issue.

VERSION:
Chrome Version: [53.0.2785.116] + [stable, beta, or dev]
Operating System: [Microsoft Windows 7 Ultimate]

REPRODUCTION STEPS
URL- chrome://settings/passwords
1. Open the aforementioned URL.
2. Highlight a an account, and click on show password.
3. If the computer has a password, enter the password and view it. If the computer does not have a password, passwords can be viewed without any restriction.

This is a major security bug, as it risks the confidential data of several people. People can view the account, password, and then do whatever they want with others' account by a mere view of these passwords, resulting from this security bug. It would be severely affecting the privacy in areas where shared computers are used, like computer labs or cyber cafes. Please fix this issue, by at least not allowing the viewing of passwords. In computers with no passwords, this is really very privacy intruding.

 

Comment 1 by dvadym@chromium.org, Sep 27 2016

Components: UI>Browser>Passwords

Comment 2 by vabr@chromium.org, Sep 27 2016

Status: WontFix (was: Untriaged)
This is working as intended. The security risk here is the local computer not having an OS-level password. Chrome itself cannot defend against local attacks, see https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-.

Sign in to add a comment