New issue
Advanced search Search tips

Issue 675885 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Automatic fill in of password, when changing password.

Reported by f0503...@gmail.com, Dec 20 2016

Issue description

I use chrome to access my gmail account. 
Like many people I have clicked on "save my password" for easy fast access to my gmail account, which is the primary and only motive for which my friends and I save our passwords, to avoid typing it every time. 
The other day, I wanted to change my password, and when I clicked to change it, the screen prompted me to the log in screen, which automatically filled since I had saved my password.
 
The issue is that the additional security step of re-logging in prompt to change a password, is defeated at the moment the screen auto fills for the users who have saved their password before. 
It shouldnt autofill, because if I let anyone lay hands on my computer, with a saved password(without telling them the password) they can easily change the password automatically, either on purpose or by accident.
 
video-1482222094.mp4
4.7 MB View Download
Components: UI>Browser>Passwords
Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
You should not share your PC with untrusted people. 

Physically local attacks (where you give someone your computer) are outside of the browser's threat model, because there are many unavoidable ways in which they can compromise your security; see https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-aren-t-physically-local-attacks-in-Chrome-s-threat-model- and https://dev.chromium.org/Home/chromium-security/security-faq#TOC-What-about-unmasking-of-passwords-with-the-developer-tools- for instance.

If you want to avoid having your password saved and available for use, you may choose not to store it. If you enable Chrome Sync, Chrome will not save your Google password: https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-doesn-t-the-Password-Manager-save-my-Google-password-if-I-am-using-Chrome-Sync-

Sign in to add a comment