Issue metadata
Sign in to add a comment
|
Security: Bug in Google Chrome saved passwords
Reported by
chiragd...@gmail.com,
Oct 3
|
||||||||||||||||||
Issue descriptionEveryone who have saved their passwords on Google account gets synced with Chrome, fine but now all passwords gets stored on device & anyone accessing my mobile can view all my passwords just by using my device security PIN or fingerprint without entering or knowing my Google account password which is one of the biggest security threat as all passwords of victim becomes accessible, which includes login details of bank or other important security data and it's extremely dangerous.
,
Oct 5
Hello and thanks for your report. What you are describing is a physically local attack: https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model It's always a good practice to use strong passwords on devices containing logged in accounts. As such, there doesn't seem to be a security vulnerability here, so I'm going to close it.
,
Oct 7
You generally share your device PIN with your friends just to allow them to access basic apps & then Google allows them to rip into your account passwords with that PIN without your approval, You are not considering this as security vulnerability? most of the times colleagues who alway stays with you might have seen your PIN, PATTERN or PASSWORDS so the person who disapproved this request doesn't seems to be educated enough about android & its security or might be one not knowing how to fix it. in this generation of developing technology we still don't have 100% accurate hardware & software and even if we get it we still have peoples using Google services on older version of devices which are not getting latest android security patch.I hope you understand it with wider perspective and try working on it.
,
Oct 7
I would just ask few questions: Why Google Chrome needs to keep passwords available offline on android device? We save passwords on Google to auto complete it while we login next time, Do you think that we can login on any site while we are offline? I think all passwords that we save on https://passwords.google.com should always stay on cloud and should be directly used while we request login and even if it stores offline on our device it should require our google password along with 2-Step verification if enabled to view any passwords and I think everyone should use some other password wallet to store their passwords safely if Google don't fix this issue on Chrome android.
,
Jan 12
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by chiragd...@gmail.com
, Oct 3