New issue
Advanced search Search tips

Issue 664898 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 3
Type: Bug



Sign in to add a comment

Only expired password works to log in

Project Member Reported by mauerer@google.com, Nov 14 2016

Issue description

Chrome Version: 55.0.2883.17 dev
Chrome OS Version: Platform 8872.15.0 (Official Build) dev-channel veyron_minnie
Chrome OS Platform: Asus Flip
Network info: N/A

Please specify Cr-* of the system to which this bug/feature applies (add
the label below).

Steps To Reproduce:
(1) Log into ChromeOS and log out
(2) Expire password on corporate account (G Suite, @google.com in this case) and change password
(3) Log in to ChromeOS - the old password works and not the new one

Expected Result:
Logging in with the old expired password throws an error and logging in with the new password succeeds

Actual Result:
Logging in with the old password succeeds and with the new one throws an error

How frequently does this problem reproduce? (Always, sometimes, hard to
reproduce?)
So far all the time (password expired recently)

What is the impact to the user, and is there a workaround? If so, what is
it?
This is a security vulnerability that is especially dangerous for business chromebook users

Please provide any additional information below. Attach a screen shot or
log if possible.
Feel free to contact me for questions

 
Components: Services>SignIn
The first time you log in after changing your password, you will have to use your old password to access local data.  After you do this once, though, you should have to use the new password.

Are you saying that you have logged out/in with the old password several times?


Status: WontFix (was: Unconfirmed)
Not able to reproduce

Comment 3 by mauerer@google.com, Apr 26 2017

Didn't see the comment 1 - yes that's exactly what happened.

Sign in to add a comment