Issue metadata
Sign in to add a comment
|
Chrome always have full access to Google Accounts
Reported by
uguu....@gmail.com,
Aug 8
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36 Steps to reproduce the problem: 1. Log into any Google service, such as gmail 2. Go to https://myaccount.google.com/permissions 3. Observe that Chrome has full access to the account. What is the expected behavior? Chrome should not have full access to Google accounts unless I explicitly grant it, which I did not. What went wrong? Chrome always have full access to Google accounts, because it is no longer possible to disable Sync. Removing access for Chrome causes me to be signed out immediately, signing back in automatically grants Chrome full access without any prompt. Did this work before? Yes 68.0.3440.84 Chrome version: 68.0.3440.106 Channel: stable OS Version: Linux version 4.9.0-7-amd64 Flash Version: Giving Chrome full access to Google accounts is too much risk, inevitably some non-Google website will exploit this to gain access. I have always disabled Sync because I did not want Chrome to sign into my Google account, and there was at least one sync related bug that I have survived due to this choice (something was related to client/server protobuf version mismatch). I would like to continue to have the option to avoid any sync related issues.
,
Aug 9
,
Aug 9
,
Aug 9
Tried testing the issue on chrome version #68.0.3440.84, reported version #68.0.3440.106 and latest chrome #70.0.3515.0 using Ubuntu 17.10, by following below steps. Steps: ===== 1.Launched chrome. 2.Signed in to the gmail account. 3.Navigated to https://myaccount.google.com/permissions able to see Chrome has full access to the account. But could not find any difference in the behaviour between chrome version #68.0.3440.84, reported version #68.0.3440.106 and latest chrome #70.0.3515.0. Attached screenshots for reference. @Reporter: Could you please review the attached screenshots and confirm if anything being missed here and request you to retry this issue with fresh profile without any extensions/apps or reset all the flags and let us know if issue still persists. Thanks.!
,
Aug 9
The problem is in previous versions of Chrome, I could opt out of Chrome sync. This appears to decouple Chrome access to Google accounts. But as of version 68.0.3440.106, it seem like I can no longer opt out of sync, and with it I must always give Chrome full access to my accounts. I understand the browser will have full access to everything I do on the web, but previously I could run Chrome with a profile and not be logged into anything, and this does not seem possible anymore.
,
Aug 9
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Aug 9
Thanks for the report! This is working as intended. It's part of our new identity system in Chrome, which we call "identity consistency." This system guarantees that the accounts you're signed into Chrome with (at the "browser level") are the same as the accounts you're signed into the web with (at the "google web service level"). We do this for consistency, so that the user is never negatively surprised by when the browser has access to their account. For example, before this change, a user may have signed out from gmail.com without realizing that they were still signed into the browser. That is no longer possible. One of the other important changes we made along with this was to decouple Sync from being signed into the browser. As you pointed out, previously some people avoided signing into the browser because it meant that they would get sync, and not everyone wants to sync. However, with these new changes, we do *not* automatically start syncing your data once you are signed into the browser. Even though Chrome has full access to your account (because you are signed in), it will not do anything with that access until you explicitly go through the Chrome sync opt-in flow. This is evident in the settings UI, where you will be able to see your account (because you are signed in) coupled with a prompt to opt into sync (see attached screenshot for an example, with my name/email redacted). If you don't choose to opt into sync, Chrome will not sync any of your data. I'm marking this as WontFix since it's working as intended.
,
Sep 24
Is there any way to be signed into Gmail but not into Chrome at all now?
,
Sep 27
Hi there! Given all the feedback we've received on this launch, we are planning to add an "opt-out" that allows users to sign into Gmail without signing into Chrome. This opt-out will also disable Chrome sign-in and sync completely. See our blog post for more details: https://www.blog.google/products/chrome/product-updates-based-your-feedback/ |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by tschumann@chromium.org
, Aug 8Components: Services>SignIn