New issue
Advanced search Search tips

Issue 804157 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 126398
Owner: ----
Closed: Jan 2018
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: A severe password bug in chrome.

Reported by harshaga...@gmail.com, Jan 21 2018

Issue description

Now this a very severe bug in chrome using which any person can see the password of a person on his/her laptop. Now since most of us have the same password in multiple accounts so this sniffing could actually be quite dangerous. Please let me know the bug bounty for this bug.
 
Labels: Needs-Feedback
You'll need to describe the bug for us to say whether it qualifies for a bounty. Based on past experience, my guess is that you're planning to report something like this: https://textslashplain.com/2017/10/16/stealing-your-own-password-is-not-a-vulnerability/

Can you please provide more details?
Oh Yes you are correct. It's like stealing your own password. But it's still very dangerous to use inspect to know the hidden password.A person might not know if someone else knows his/her password.I can just use someone else's laptop and know his/her password. Instead what you can do is provide a hash and not the actual password. The hash function being on the server side.
Screenshot (331).png
203 KB View Download
Screenshot (332).png
204 KB View Download
Project Member

Comment 3 by sheriffbot@chromium.org, Jan 21 2018

Cc: elawrence@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Mergedinto: 126398
Status: Duplicate (was: Unconfirmed)
Local attackers can undertake any number of attacks: https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model

Schemes based on hashes can be more secure than raw passwords, but require cooperation on the part of the server, and ultimately provide little marginal protection against local attacks. 
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 30 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment