New issue
Advanced search Search tips

Issue 864765 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 25
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: Exploit that allows a user to find somebody's personal passwords given that they are enrolled in a school district.

Reported by xzack.mu...@gmail.com, Jul 17

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://chromium.googlesource.com
/chromium/src/+/master/docs/security/faq.md

Please see the following link for instructions on filing security bugs:
https://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
In a school system that deploys Chromebooks, they have a default password for a google account made for the user. This password uses easily accessible information. In my school district, the formula for a password is '(first initial)(last initial)(birthday in MM/DD/YYYY)!'. The email itself is even easier, being the school 'lunch number'(a six digit number that identifies the student) @sps('SPS' is the initials for the school district).org. One can obtain the 'lunch number' by going on to a website by Google that uses the 'Share' function(i.e Google Slides). Once the person is on the website, all they have to do is type in your first and last name and it shows their email. Now, you can sign in to the user's account. That wouldn't be terrible in itself, but once the attacker has done this, all they have to do is go to Google Passwords, and if the victim saved passwords using their 'main' password, the Attacker can access the user's home passwords. This attack targets the most susceptible groups, being children. 

VERSION
Chrome Version: 67.0.3396.99 stable
Operating System: Windows 10 Version 1803, 17134.165 OS Build (They don't do service packs anymore)

REPRODUCTION CASE
This case can't be replicated in a single website as it is more of an exploit of given features. I'll add here that I'm not entirely sure that this fits the profile of something that I can report with this, but it still needs to be resolved.

POSSIBLE FIXES
I'll list the possible fixes that come to mind:
Make the format of passwords for students use information that is harder to access.
Block the use of Google Passwords on school accounts.
Allow users enrolled by the district to change their password.

OTHER NOTES
I have noticed that if you sign in on a computer that isn't a school owned Chromebook, you can adjust your password, but the average student most likely wouldn't go through this hassle if they weren't aware that there personal passwords could be accessed.
 
Labels: -Type-Bug-Security Type-Bug
Thanks for the report.

The first suggestion of making passwords less guessable is something you'd have to take up with the school district. Many schools intentionally use semi-guessable passwords to avoid the burden of student's forgetting them. Similarly for the third suggestion -- that is a policy decision for the school to make.

Unfortunately in this situation it sounds like the devices are not entirely suitable for personal use. Are personal accounts (using personal Google accounts, for example) allowed on these devices? If so, separating personal browsing from school browsing by using multiple Chrome accounts may be preferred, although this distinction between the managed account and the personal account may not be obvious to students unless they were told about it.

Either way, this sounds like a school policy issue rather than something Chrome/OS can handle. If the school technology administrators are concerned about this, they may want to turn off the Password Manager using an enterprise policy setting https://www.chromium.org/administrators/policy-list-3#PasswordManager.

If you think there are management features missing that are desired to address this, we can turn this into a request for those features, otherwise this sounds like something we can't fix.
Status: WontFix (was: Unconfirmed)
Closing this since it doesn't seem there's anything to do here.

If you think there are functional issues with managing the devices or features that would make help address this concern, please file a normal (public) bug.
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 1

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment