Password manager allows user to view passwords without authenticating on Linux
Reported by
benwmora...@gmail.com,
Dec 8 2016
|
||||
Issue descriptionUserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.100 Safari/537.36 Steps to reproduce the problem: 1. Settings > Advanced Settings > Manage Passwords 2. Show Passwords What is the expected behavior? When I go to passwords.google.com, I have to sign in before being able to view managed passwords. I'd expect to have to authenticate when going through the browser, but I don't. What went wrong? I can view my passwords without authenticating. My Mac requires that I type a password before viewing, but my Ubuntu 16.04 machine can view it without a prompt. I'm not sure if it's an issue on Chrome's side or Ubuntu. Did this work before? N/A Chrome version: 54.0.2840.100 Channel: n/a OS Version: Flash Version: Shockwave Flash 23.0 r0
,
Dec 8 2016
https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model-
,
Dec 8 2016
Removing security flags (per comment #2) but sending to the Password Manager team to consider as a functionality bug or otherwise explain why Linux differs here.
,
Dec 13 2016
This is known. Neither GNU/Linux nor Chrome OS reauthenticate the user before allowing to view the passwords. It is unfortunate that this feature is inconsistent across platforms, but changing it has negligible priority, given that there are basically no benefits (see #2).
,
Feb 26 2017
Issue 696330 has been merged into this issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by elawrence@chromium.org
, Dec 8 2016Status: Untriaged (was: Unconfirmed)
Summary: View passwords without authenticating on Linux (was: View passwords without authenticating)