Viewing saved passwords
Reported by
vanajvid...@gmail.com,
Sep 23 2016
|
||
Issue descriptionThis template is ONLY for reporting privacy issues. Please use a different template for other types of bug reports. Please see http://www.chromium.org/Home/chromium-privacy for further information. PRIVACY ISSUE Please provide a brief summary of the privacy issue. VERSION: Chrome Version: [53.0.2785.116] + [stable, beta, or dev] Operating System: [Microsoft Windows 7 Ultimate] REPRODUCTION STEPS URL- chrome://settings/passwords 1. Open the aforementioned URL. 2. Highlight a an account, and click on show password. 3. If the computer has a password, enter the password and view it. If the computer does not have a password, passwords can be viewed without any restriction. This is a major security bug, as it risks the confidential data of several people. People can view the account, password, and then do whatever they want with others' account by a mere view of these passwords, resulting from this security bug. It would be severely affecting the privacy in areas where shared computers are used, like computer labs or cyber cafes. Please fix this issue, by at least not allowing the viewing of passwords. In computers with no passwords, this is really very privacy intruding.
,
Sep 27 2016
This is working as intended. The security risk here is the local computer not having an OS-level password. Chrome itself cannot defend against local attacks, see https://www.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-. |
||
►
Sign in to add a comment |
||
Comment 1 by dvadym@chromium.org
, Sep 27 2016