New issue
Advanced search Search tips

Issue 812159 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 781675
Owner: ----
Closed: Feb 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Password manager shows password length

Reported by ram.puru...@gmail.com, Feb 14 2018

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Saved password length is visible in the password manager  

VERSION
Version 63.0.3239.132 (Official Build) (64-bit)
Operating System: [Windows, Windows10]

REPRODUCTION CASE
The length of the password which is stored in the system is the first way to hack the password.For example if i have saved my password by mistake in the public internet center then it might lead to compromise of my account. In case of home it might lead to lose of privacy i have also included the screenshot of the place where i found this thing.

I have uploaded 1st step image in which we can disable the show icon option.

If the particular link is clicked then the page is opened with the store password like the image i have attached as "Before password show" then password can be view by changing the value in inspect element as "After Password Show" in the image its better to disable this option in the chrome for save password to improve the security.

if its possible i can also give the clear detail on this in the upcoming mail if you guys are interested but from my view this is one of the bigger security bug.

I have also raised the same  bug 14  weeks back but its closed.
Have also included the images through the following mail please mail back for more detail.



 
Components: Blink>Forms>Password
Mergedinto: 781675
Status: Duplicate (was: Unconfirmed)
Summary: Security: Password manager shows password length (was: Security: )
Please do not file the same bug repeatedly, it simply wastes everyone's time.

Stealing your own password is not a vulnerability.

While the Password Manager reveals the length, it's also trivial to reveal the password itself, as you can see in this video: https://textslashplain.com/2017/10/16/stealing-your-own-password-is-not-a-vulnerability/

https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#What-about-unmasking-of-passwords-with-the-developer-tools

Use an OS user account with a password / screen lock to protect your password on your own PC.

It is never secure to enter any private data, including passwords, on a PC you don't control (like a kiosk or internet cafe), because the PC may be compromised with spyware: https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model
Project Member

Comment 2 by sheriffbot@chromium.org, May 23 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment