New issue
Advanced search Search tips

Issue 684809 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 678518
Owner:
Closed: Jan 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

after password change of google account synced passwords on chrome continue to be available even without entering new password

Reported by emo...@gmail.com, Jan 24 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36

Steps to reproduce the problem:
1. I'm syncing my passwords between some PCs in Chrome. 
2. I have changed my pass for google profile
3. All passwords are still available in all PCs even without entering new pass on all of them

What is the expected behavior?
After change of a google profile pass, all devices/chromes where personal passwords are stored/synced should stop offer auto-filing of passwords unless the new password is entered. All passwords in chrome/settings should not be visible unless correct google password is entered. 

What went wrong?
I lost my PC where I have Chrome installed with stored/synced passwords. I have changed my google profile password to prevent security issues. After changing of google profile password, I cheched on other machine (third one) and all passwords continue to be available even i didn't entered in chrome my new password. I think in case of theft of PC, changing google password can't prevent security leakage of personal passwords. 

Did this work before? No 

Chrome version: 55.0.2883.87  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 24.0 r0

PLEASE contact me to explain what test i have made. Thanks!
 

Comment 1 by est...@chromium.org, Jan 24 2017

Components: UI>Browser>Passwords
Owner: sabineb@chromium.org
Sabine, could you take a look at this and say if it's WAI or not? i.e. If you change your Google password should you become logged out of Chrome on other devices?

Thanks!
Is this a duplicate of  Issue 678518 ?

Comment 3 by est...@chromium.org, Jan 25 2017

Mergedinto: 678518
Status: Duplicate (was: Unconfirmed)
Looks like it, thanks. Based on that bug, this is WAI; changing your Google password doesn't sign you out of other Chrome instances, but it does stop syncing on those devices.
Yes, estark is correct. 
Project Member

Comment 5 by sheriffbot@chromium.org, May 3 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment