New issue
Advanced search Search tips

Issue 829336 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: Possible improper access control to synchronized passwords on Chrome

Reported by sorrisod...@gmail.com, Apr 5 2018

Issue description

Steps to reproduce:

  1. access chrome://settings/syncSetup > set a long password > logout
  2. access the account again using the Chrome login (direct on browser)

When the synchronization is started the long password will be required for this to happen and then I can have access to the synchronized cryptographic data using the long password > dont insert it

  3. access chrome://settings/passwords 

You can view saved passwords here even without entering the long password that should decrypt this data

Browser/OS: Chrome 65.0.3325.181
 
What Operating System are you using?

You are basically requesting that the Chrome Password Manager be protected by some sort of Master Password, right?

( Issue 613477 )
Hi,

Iam using an Windows 7 Ultimate 32 bits 

You are basically requesting that the Chrome Password Manager be protected by some sort of Master Password, right?

I think it's something about that. If there is a master password (long password) to encrypt all data including passwords it is not required to access passwords saved in chrome://settings/passwords
Other info: I realized that even without logging in to Chrome it is possible to view passwords saved in chrome://settings/passwords

I believed logging into Google account this could be loaded (even without entering the long password) but even without logging the passwords are accessible
Do you have a Windows login password configured (e.g. when you restart your PC)? Are you promoted to enter that when unmasking a password on the Settings page?
The password is requested if there is one for this device. If not, direct access to the stored passwords

But I noticed additional behavior where this is not necessary:

- when passwords are saved Chrome offers the autocomplete login form > simply access the login page of sites that have passwords stored in Chrome and change the type of 'password' field to 'text'
Yup, it sounds like this is working as expected then.

As to the use of Developer Tools, yes, this is a well-understood issue, mentioned in 613477 and more prominently here: https://textslashplain.com/2017/10/16/stealing-your-own-password-is-not-a-vulnerability/
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Status: WontFix (was: Unconfirmed)
Agree with #6. 

Mark as work-as-intended.

Sign in to add a comment