New issue
Advanced search Search tips

Issue 689629 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: Saved passwords on chrome are easy to retrieve

Reported by akku...@gmail.com, Feb 7 2017

Issue description

Sir/Ma'am

Recently, i was using one of my friends laptop and opened a website on which his credentials were saved. For a moment i stopped there and opened inspect element on google chrome and change the field of password as type="text" instead of password, this allowed me see his password.

Later, i tried this on other websites like www.facebook.com , mail.google.com
and now i know his password.

So, i don't think that this Save Password feature of google chrome is good enough to keep my passwords safe, secure and encrypted.

I have attached the screenshot of one such case where i can see the password just with a simple editing. Although it will change again to type="password" but still this is enough for anyone to breach into our privacy.

I hope you would consider this 
 
2017-02-08.png
197 KB View Download
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Status: WontFix (was: Unconfirmed)
Thanks for reporting, akkug95@. However, we'll consider it as work as intended.

Since you're already using your friends' chrome profile to browser, security boundaries are already breached. Therefore, there is very little we can do. In fact, I bet there are other easier ways to see her/his passwords if you're browsing in her/his session (or even change her/his passwords :-P).

Next time, please convince your friend to crease a guest profile for you to use.

 

Comment 2 by akku...@gmail.com, Feb 7 2017

I told my friend already ( good friend ) and he has changed his password.
However, with this I'm more conscious with saved passwords and thought of
reporting this issue as i'm sure many of other people may have also been
victim of this

Sign in to add a comment