New issue
Advanced search Search tips

Issue 818443 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2018
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

facebook login security issue

Reported by hemanthk...@gmail.com, Mar 3 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.186 Safari/537.36

Steps to reproduce the problem:
1. login fb in chrome and save the password login your facebook account and logout.chrome saves your password and appears on the screen. 
2. click on the facebook mail id edit the number present in the name.for example- my mail id id hemanthkumar0917@gmail.com i have edited my mail id number and changed it to hemanthkumar0965@gmail.com and finally my account has logged in with wrong mail id number.
3. again the browser asks the user to save password with wrong mailid number and if the user saves and again changed the mail id number and logged in it log into the same account and its a cyclic process if we keep on going.

What is the expected behavior?
security login issues arrise and most of the people in india use internet centres to login their facebook accounts and for their convienience yhey intentionally save their passwords and gifted with a threat to their accounts.

What went wrong?
chrome browser save password prompt had a bug in it.if i had opened my facebook in chrome and prompt comes to save my id and password in 128 bit security and logged in and loggedout.The saved id and password reappears as i saved it.in that mail id for example-my facebook mail id is hemanthkumar0917@gmail.com and if i had changed my id number to hemanthkumar0967@gmail.com or any number it logins my account. 

Did this work before? Yes present version

Chrome version: 64.0.3282.186  Channel: stable
OS Version: 10.0
Flash Version: 

all is this you have to re-ensure the text case and resolve the code or else it will cause lot of privacy issues.
 
chrome bug 1.PNG
157 KB View Download
chrome bug 2.PNG
455 KB View Download
chrome bug3.PNG
157 KB View Download
chrome bug 4.PNG
453 KB View Download
Status: WontFix (was: Unconfirmed)
This does not describe a security vulnerability in Google Chrome. If Facebook allows you to log into an account using the "wrong" email ID, this would reflect an issue in Facebook itself, not in Google Chrome. 

Google Chrome's password manager dutifully offers to remember the information you entered into the web page; if you enter in account information and successfully log in, Chrome will offer to store that information-- it has no way to determine whether the information is "correct" beyond whether or not the website accepts the information.

It seems remotely possible that Facebook will intentionally allow you to log into the site with typos in the username information. For instance, we know from a prior investigation that Facebook uses special code to allow the user to log into their account even with a slightly-incorrect password [1]; perhaps they have similar code to allow a slightly-incorrect username.


[1] https://bugs.chromium.org/p/chromium/issues/detail?id=749712#c2
I've confirmed that Facebook does indeed permit you to log in with typos in your username. For instance, I have account 78e@live.com and I can log in using 78ee@live.com.

This is not an issue in Chrome, but rather a design decision on Facebook's part.
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 10 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment