New issue
Advanced search Search tips

Issue 864687 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 17
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: get stored password from xhr

Reported by nagy...@gmail.com, Jul 17

Issue description

Currently under settings->advanced->managed password if you want passwords to show you need to enter your windows password. I realized that, from the Chrome DevTools you can get that data without any knowledge of the OS password.

On any HTTPS site any person with access to another's computer has the ability to log in with the other's previously saved credentials, but with a little workaround the person can easily get the saved password from the Chrome DevTools.

If the person opens the DevTools->Network before the person presses the submit button, the person can retrieve the other's password in plain text from the xhr.
 
Labels: Needs-Feedback
If someone can run an arbitrary process as the same user, I don't believe DPAPI on Windows (which is what Chrome uses to store account-encrypted data such as stored passwords) will protect the data stored.

To make sure I understand the issue being reported, could you provide more explicit reproduction steps (particularly, what do you mean by "with a little workaround")?

Status: WontFix (was: Unconfirmed)
In fact, it's even easier than that. See https://dev.chromium.org/Home/chromium-security/security-faq#TOC-What-about-unmasking-of-passwords-with-the-developer-tools- for an equivalent situation, and why its not a problem.

Feel free to re-open the bug if I've mis-interpreted what you're saying.
Thank you for your comments. It is clear after reading the article provided in Comment 2.
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 24

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment